CVE-2026-64252
Fecha de publicación:
24/07/2026
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
MIPS: DEC: Prevent initial console buffer from landing in XKPHYS<br />
<br />
In 64-bit configurations calling the initial console output handler from<br />
a kernel thread other than the initial one will result in a situation<br />
where the stack has been placed in the XKPHYS 64-bit memory segment and<br />
consequently so has been the buffer allocated there that is used as the<br />
argument corresponding to the `%s&#39; output conversion specifier for the<br />
firmware&#39;s printf() entry point.<br />
<br />
This 64-bit address will then be truncated by 32-bit firmware, resulting<br />
in an attempt to access the wrong memory location, which in turn will<br />
cause all kinds of unpredictable behaviour, such as a kernel crash:<br />
<br />
Console: colour dummy device 160x64<br />
Calibrating delay loop... 49.36 BogoMIPS (lpj=192512)<br />
pid_max: default: 32768 minimum: 301<br />
CPU 0 Unable to handle kernel paging request at virtual address 000000000203bd00, epc == ffffffffbfc08364, ra == ffffffffbfc08800<br />
Oops[#1]:<br />
CPU: 0 PID: 0 Comm: swapper Not tainted 5.18.0-rc2-00254-gfb649bda6f56-dirty #121<br />
$ 0 : 0000000000000000 0000000000000001 0000000000000023 ffffffff80684ba0<br />
$ 4 : 000000000203bd00 ffffffffbfc0f3b4 ffffffffffffffff 0000000000000073<br />
$ 8 : 0a303d7469000000 0000000000000000 0000000000000073 ffffffffbfc0f473<br />
$12 : 0000000000000002 0000000000000000 ffffffff80684c1c 0000000000000000<br />
$16 : 0000000000000000 ffffffff80596dc9 0000000000000000 ffffffffbfc09240<br />
$20 : ffffffff80684c40 ffffffffbfc0f400 000000000000002d 000000000000002b<br />
$24 : ffffffffffffffbf 000000000203bd00<br />
$28 : ffffffff805f0000 ffffffff80684b58 0000000000000030 ffffffffbfc08800<br />
Hi : 0000000000000000<br />
Lo : 0000000000000aa8<br />
epc : ffffffffbfc08364 0xffffffffbfc08364<br />
ra : ffffffffbfc08800 0xffffffffbfc08800<br />
Status: 140120e2 KX SX UX KERNEL EXL<br />
Cause : 00000008 (ExcCode 02)<br />
BadVA : 000000000203bd00<br />
PrId : 00000430 (R4000SC)<br />
Modules linked in:<br />
Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____), tls=0000000000000000)<br />
Stack : 0000000000000000 0000000000000000 0000000000000000 0000004d0000004d<br />
80684cc0806a2a40 80596dc80000004d 8061000000000000 bfc0850c80684c38<br />
0000000000000000 000000000203bd00 0000000000000000 0000000000000000<br />
0000000000000000 00000000bfc0f3b4 0000000000000000 0000000000000000<br />
0000000000000000 0000000000000000 0000000000000000 0000000000000000<br />
0000000000000000 0000000000000000 0000000000000000 0000000000000000<br />
0000002500000000 0000000000000000 0000000000000000 802c1a7400000000<br />
0203bd0080596dc8 0203bd4d69000000 6c61632000000018 5f746567646e6172<br />
6c616320625f6d6f 5f736e5f6d6f7266 206361323778302b 303d74696e726320<br />
806a0a38806b0000 806a0a38806b0000 00000000806b0000 80683c58806b0000<br />
...<br />
Call Trace:<br />
<br />
Code: a082ffff 03e00008 00601021 00001821 10400005 24840001 80820000 24630001<br />
<br />
---[ end trace 0000000000000000 ]---<br />
Kernel panic - not syncing: Fatal exception in interrupt<br />
<br />
KN04 V2.1k (PC: 0xa0026768, SP: 0x806848e8)<br />
>><br />
<br />
In this case the pointer in $4 was truncated from 0x980000000203bd00 to<br />
0x000000000203bd00.<br />
<br />
This may happen when no final console driver has been enabled in the<br />
configuration and consequently the initial console continues being used<br />
late into bootstrap or with an upcoming change that will switch the zs<br />
driver to use a platform device, which in turn will make the console<br />
handover happen only after other kernel threads have already been<br />
started.<br />
<br />
Fix the issue by making the buffer static and initdata, and therefore<br />
placed in the CKSEG0 32-bit compatibility segment, observing that the<br />
console output handler is called with the console lock held, implying<br />
no need for this code to be reentrant. Add an assertion to verify the<br />
buffer actually has been placed in a compatibility segment.
Gravedad: Pendiente de análisis
Última modificación:
24/07/2026