CVE-2026-53282: x86/kexec: Push kjump return address even for non-kjump kexec

Published Jun 26, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

x86/kexec: Push kjump return address even for non-kjump kexec

The version of purgatory code shipped by kexec-tools attempts to look above the top of its stack to find a return address for a kjump, even in a non-kjump kexec.

After the commit in Fixes: the word above the stack might not be there, leading to a fault (which is at least now caught by my exception-handling code in kexec).

That commit fixed things for the actual kjump path, but no longer "gratuitously" pushes the unused return address to the stack in the non-kjump path. Put that back in the non-kjump path, to prevent purgatory from crashing when trying to access it.

Affected Software

5 affected components
Linux Linux kernel>=6.14<6.18.33
Linux Linux kernel>=6.19<7.0.10
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3

Event History

Jun 26, 2026
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
Description
Data Sourced
via NVD·08:17 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

Who could exploit this issue?

Exploitation requires local access and low privileges. No user interaction is required, and the CVSS vector does not indicate a remote attack path.

2

Which deployments are exposed?

The issue applies to x86 Linux kernel systems that perform a non-kjump kexec using the affected purgatory code shipped by kexec-tools. The described failure occurs when that code reads above the top of its stack for a return address.

3

What is the expected security impact?

The impact is a crash during the affected kexec flow, resulting in high availability impact. The provided CVSS assessment indicates no confidentiality or integrity impact.

4

What should be done if this system uses kexec?

Apply an available patch for the Linux kernel. If patching cannot occur immediately, avoid the affected non-kjump kexec operation where operationally possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203