LoongArch: Fix address space mismatch in kexec command line lookup
Published Aug 12, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.21%
Description
When searching the loaded segments for the "kexec" command line marker, the kexec_load(2) path (file_mode == 0) passes the user-space segment buffer straight to strncmp() through a bogus (char __user *) cast. This dereferences a user pointer in kernel context, which is wrong and is flagged by sparse:
arch/loongarch/kernel/machine_kexec.c:84:51: sparse: incorrect type in argument 2 (different address spaces) @@ expected char const * @@ got char [noderef] __user *
Here copy the marker-sized prefix of each segment into a small on-stack buffer with copy_from_user() before comparing, and skip segments that fault. The subsequent copy_from_user() that stages the full command line into the safe area is left unchanged.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.1StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.1
- Version 6.18.42StatusunaffectedConstraints<=6.18.*
- Version 7.1.6StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
Red Hat Enterprise Linux for NVIDIA 26
kernel
Out of support scope
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux for NVIDIA 26 | kernel | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects LoongArch systems using kexec_load(). The kernel incorrectly dereferences user-space segment buffers when searching for the kexec command line marker. Systems not using LoongArch are not affected.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-68435 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2514452 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57043 Advisory
- https://git.kernel.org/stable/c/485ed44db5694d8d2e5027f63ad608e705286f30
- https://git.kernel.org/stable/c/7a54e0cbaad4a5a09e7cc7a4f05d181048e98ca7
- https://git.kernel.org/stable/c/a94d6726ec8680a2b0c453fc782a543f68a1ea06
- https://lore.kernel.org/linux-cve-announce/2026081255-CVE-2026-68435-6d41@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-68435
- https://www.cve.org/CVERecord?id=CVE-2026-68435
Change history (0)
No recorded changes yet.