CVE-2026-68455: liveupdate: validate session type before performing operation
In the Linux kernel, the following vulnerability has been resolved:
liveupdate: validate session type before performing operation
The sessions ioctls are not applicable to all session types. PRESERVEFD is only applicable to outgoing sessions. RETRIEVEFD and FINISH are only valid for incoming session. Calling a incoming ioctl on an outgoing session is invalid and can cause file handlers to run into unexpected errors.
For example, a user can create a (outgoing) session, preserve a memfd, and then immediately do a retrieve without doing a kexec in between. This would result in memfd's retrieve handler to run. The handlers expects to be called from a post-kexec context, and will try to do a khorestorevmalloc() or khorestorefolio() to try and restore memory.
KHO catches this (thanks to KHOPAGEMAGIC) and returns an error, but since this is considered an internal error and KHO throws out a bunch of WARN()s.
Associate a type with each ioctl op and validate the type in luosessionioctl() before dispatching the ioctl handler to make sure the op is being called for the right session type.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In luo_session_ioctl(), validate that the session is of the correct type before dispatching the ioctl handler (e.g., ensure PRESERVE_FD/RETRIEVE_FD/FINISH are only invoked for outgoing sessions). If the session type is invalid, fail the ioctl to prevent file/memfd handlers from running in unexpected (incoming) contexts.
Linux kernel (luo_session_ioctl / session ioctl dispatcher) session type validation = validate session type before dispatching ioctl handler
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68455?
The severity of CVE-2026-68455 is rated as 17, indicating a significant risk.
How do I fix CVE-2026-68455?
To fix CVE-2026-68455, ensure that you are running the latest patched version of the Linux kernel.
What systems are affected by CVE-2026-68455?
CVE-2026-68455 affects systems running the vulnerable versions of the Linux kernel where liveupdate operations are performed.
What types of sessions are impacted by CVE-2026-68455?
CVE-2026-68455 impacts session operations that do not validate session types correctly, particularly affecting outgoing and incoming sessions.
Is CVE-2026-68455 a critical vulnerability?
CVE-2026-68455 is not classified as critical but poses a risk that should be addressed in affected systems.