x86/kexec: Push kjump return address even for non-kjump kexec
Summary
| CVE | CVE-2026-53282 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-26 20:17:20 UTC |
| Updated | 2026-06-26 20:17:20 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
x86/kexec: Push kjump return address even for non-kjump kexec
The version of purgatory code shipped by kexec-tools attempts to look above
the top of its stack to find a return address for a kjump, even in a non-kjump
kexec.
After the commit in Fixes: the word above the stack might not be there,
leading to a fault (which is at least now caught by my exception-handling code
in kexec).
That commit fixed things for the actual kjump path, but no longer
"gratuitously" pushes the unused return address to the stack in the non-kjump
path. Put that *back* in the non-kjump path, to prevent purgatory from
crashing when trying to access it. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 2cacf7f23a024ab1fdc603ca6a4f4c8b2de9f64e b0bd7a850e1f082560959707dbf57b0402071646 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2cacf7f23a024ab1fdc603ca6a4f4c8b2de9f64e 7dba9631faa2ee0785e8c2bf0e3d90a05f26dd8c git |
Not specified |
| CNA |
Linux |
Linux |
affected 2cacf7f23a024ab1fdc603ca6a4f4c8b2de9f64e 786a45757dcdf8f2beb9d4a6db605db16c18b2b4 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.14 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.14 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.33 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0.10 7.0.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/7dba9631faa2ee0785e8c2bf0e3d90a05f26dd8c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/786a45757dcdf8f2beb9d4a6db605db16c18b2b4 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b0bd7a850e1f082560959707dbf57b0402071646 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.