CVE-2026-53282: x86/kexec: Push kjump return address even for non-kjump kexec
In the Linux kernel, the following vulnerability has been resolved:
x86/kexec: Push kjump return address even for non-kjump kexec
The version of purgatory code shipped by kexec-tools attempts to look above the top of its stack to find a return address for a kjump, even in a non-kjump kexec.
After the commit in Fixes: the word above the stack might not be there, leading to a fault (which is at least now caught by my exception-handling code in kexec).
That commit fixed things for the actual kjump path, but no longer "gratuitously" pushes the unused return address to the stack in the non-kjump path. Put that back in the non-kjump path, to prevent purgatory from crashing when trying to access it.
Affected Software
Remediation
Event History
Frequently Asked Questions
Who could exploit this issue?
Exploitation requires local access and low privileges. No user interaction is required, and the CVSS vector does not indicate a remote attack path.
Which deployments are exposed?
The issue applies to x86 Linux kernel systems that perform a non-kjump kexec using the affected purgatory code shipped by kexec-tools. The described failure occurs when that code reads above the top of its stack for a return address.
What is the expected security impact?
The impact is a crash during the affected kexec flow, resulting in high availability impact. The provided CVSS assessment indicates no confidentiality or integrity impact.
What should be done if this system uses kexec?
Apply an available patch for the Linux kernel. If patching cannot occur immediately, avoid the affected non-kjump kexec operation where operationally possible.