In the Linux kernel, the following vulnerability has been resolved:
kho: skip KHO for crash kernel
khofillkimage() unconditionally populates the kimage with KHO metadata for every kexec image type. When the image is a crash kernel, this can be problematic as the crash kernel can run in a small reserved region and the KHO scratch areas can sit outside it. The crash kernel then faults during khomemoryinit() when it tries phystovirt() on the KHO FDT address:
Unable to handle kernel paging request at virtual address xxxxxxxx ... fdtoffsetptr+... fdtchecknodeoffset+... fdtfirstpropertyoffset+... fdtgetpropertynamelen_+... fdtgetprop+... khomemoryinit+... mmcoreinit+... startkernel+...
kholocatememhole() already skips KHO logic for KEXECTYPECRASH images, but khofillkimage() was missing the same guard. As khofillkimage() is the single point that populates image->kho.fdt and image->kho.scratch, fixing it here is sufficient for both arm64 and x86 as the FDT and bootparams path are bailing out when these fields are unset.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64167.json"
}