CVE-2026-43129: ima: verify the previous kernel's IMA buffer lies in addressable RAM

Published May 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ima: verify the previous kernel's IMA buffer lies in addressable RAM

Patch series "Address page fault in imarestoremeasurementlist()", v3.

When the second-stage kernel is booted via kexec with a limiting command line such as "mem=<size>" we observe a pafe fault that happens.

BUG: unable to handle page fault for address: ffff97793ff47000 RIP: imarestoremeasurementlist+0xdc/0x45a #PF: errorcode(0x0000) not-present page

This happens on x8664 only, as this is already fixed in aarch64 in commit: cbf9c4b9617b ("of: check previous kernel's ima-kexec-buffer against memory bounds")

This patch (of 3):

When the second-stage kernel is booted with a limiting command line (e.g. "mem=<size>"), the IMA measurement buffer handed over from the previous kernel may fall outside the addressable RAM of the new kernel. Accessing such a buffer can fault during early restore.

Introduce a small generic helper, imavalidaterange(), which verifies that a physical [start, end] range for the previous-kernel IMA buffer lies within addressable memory: - On x86, use pfnrangeismapped(). - On OF based architectures, use pageisram().

Affected Software

4 affected components
Linux Linux kernel
Linux Linux kernel>=6.0<6.12.77
Linux Linux kernel>=6.13<6.18.16
Linux Linux kernel>=6.19<6.19.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Linux kernel to a version that resolves this vulnerability.

    Patch cbf9c4b9617b

Event History

May 6, 2026
CVE Published
via MITRE·11:27 AM
Data Sourced
via MITRE·11:27 AM
Description
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

Which systems are realistically exposed?

Exposure requires a system that boots a second-stage Linux kernel through kexec and uses a memory-limiting kernel command line such as "mem=<size>". The reported fault condition is specific to x86_64; the issue was already addressed for aarch64.

2

What conditions are needed to trigger the failure?

An attacker does not need network access or user interaction under the provided CVSS vector, but exploitation requires local low-privileged access. The vulnerable condition also depends on the previous kernel handing over an IMA measurement buffer that falls outside the new kernel's addressable RAM.

3

How can I tell whether a system is affected?

The observable symptom is an early boot page fault in ima_restore_measurement_list(), potentially logged as "BUG: unable to handle page fault" with a non-present page error. This occurs when restoring the previous kernel's IMA measurement list after a kexec boot with restricted memory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203