Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-53282

MEDIUM · 5.5 CVSS Gepubliceerd:

Beschrijving NL

In de Linux kernel is de volgende kwetsbaarheid verholpen:

x86/kexec: Druk kjump retouradres zelfs voor niet-kjump kexec

De versie van de vagevuurcode die door kexec-tools wordt verzonden, probeert hierboven te kijken
de bovenkant van de stapel om een retouradres te vinden voor een kjump, zelfs in een niet-kjump
kexec. Na de commit in Fixes: het woord boven de stack staat er misschien niet,
wat leidt tot een fout (die in ieder geval nu wordt opgevangen door mijn exception-handling code
in kexec). Die vaste dingen vastleggen voor het eigenlijke kjump-pad, maar niet langer
"onnodig" duwt het ongebruikte retouradres naar de stapel in de niet-kjump
pad. Zet dat *terug* in het niet-kjump pad, om te voorkomen dat het vagevuur
crashen wanneer je er toegang toe probeert te krijgen.

Origineel (Engels) tonen

In the Linux kernel, the following vulnerability has been resolved:

x86/kexec: Push kjump return address even for non-kjump kexec

The version of purgatory code shipped by kexec-tools attempts to look above
the top of its stack to find a return address for a kjump, even in a non-kjump
kexec.

After the commit in Fixes: the word above the stack might not be there,
leading to a fault (which is at least now caught by my exception-handling code
in kexec).

That commit fixed things for the actual kjump path, but no longer
"gratuitously" pushes the unused return address to the stack in the non-kjump
path. Put that *back* in the non-kjump path, to prevent purgatory from
crashing when trying to access it.

Vendors

Linux

Affected products

Linux Kernel

References