PT-2026-61484 · Linux+1 · Linux Kernel+1

CVE-2026-64167

·

Published

2026-04-28

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists where the kho fill kimage() function unconditionally populates the kimage with KHO metadata for every kexec image type. When a crash kernel is used, it may operate within a small reserved region, causing KHO scratch areas to be located outside this region. This leads to a kernel paging request fault during kho memory init() when the system attempts to perform phys to virt() on the KHO FDT address. This occurs because kho fill kimage() lacked the guard present in kho locate mem hole() to skip KHO logic for KEXEC TYPE CRASH images.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14301
CVE-2026-64167
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu