Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64252

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/07/2026
Última modificación:
24/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> MIPS: DEC: Prevent initial console buffer from landing in XKPHYS<br /> <br /> In 64-bit configurations calling the initial console output handler from<br /> a kernel thread other than the initial one will result in a situation<br /> where the stack has been placed in the XKPHYS 64-bit memory segment and<br /> consequently so has been the buffer allocated there that is used as the<br /> argument corresponding to the `%s&amp;#39; output conversion specifier for the<br /> firmware&amp;#39;s printf() entry point.<br /> <br /> This 64-bit address will then be truncated by 32-bit firmware, resulting<br /> in an attempt to access the wrong memory location, which in turn will<br /> cause all kinds of unpredictable behaviour, such as a kernel crash:<br /> <br /> Console: colour dummy device 160x64<br /> Calibrating delay loop... 49.36 BogoMIPS (lpj=192512)<br /> pid_max: default: 32768 minimum: 301<br /> CPU 0 Unable to handle kernel paging request at virtual address 000000000203bd00, epc == ffffffffbfc08364, ra == ffffffffbfc08800<br /> Oops[#1]:<br /> CPU: 0 PID: 0 Comm: swapper Not tainted 5.18.0-rc2-00254-gfb649bda6f56-dirty #121<br /> $ 0 : 0000000000000000 0000000000000001 0000000000000023 ffffffff80684ba0<br /> $ 4 : 000000000203bd00 ffffffffbfc0f3b4 ffffffffffffffff 0000000000000073<br /> $ 8 : 0a303d7469000000 0000000000000000 0000000000000073 ffffffffbfc0f473<br /> $12 : 0000000000000002 0000000000000000 ffffffff80684c1c 0000000000000000<br /> $16 : 0000000000000000 ffffffff80596dc9 0000000000000000 ffffffffbfc09240<br /> $20 : ffffffff80684c40 ffffffffbfc0f400 000000000000002d 000000000000002b<br /> $24 : ffffffffffffffbf 000000000203bd00<br /> $28 : ffffffff805f0000 ffffffff80684b58 0000000000000030 ffffffffbfc08800<br /> Hi : 0000000000000000<br /> Lo : 0000000000000aa8<br /> epc : ffffffffbfc08364 0xffffffffbfc08364<br /> ra : ffffffffbfc08800 0xffffffffbfc08800<br /> Status: 140120e2 KX SX UX KERNEL EXL<br /> Cause : 00000008 (ExcCode 02)<br /> BadVA : 000000000203bd00<br /> PrId : 00000430 (R4000SC)<br /> Modules linked in:<br /> Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____), tls=0000000000000000)<br /> Stack : 0000000000000000 0000000000000000 0000000000000000 0000004d0000004d<br /> 80684cc0806a2a40 80596dc80000004d 8061000000000000 bfc0850c80684c38<br /> 0000000000000000 000000000203bd00 0000000000000000 0000000000000000<br /> 0000000000000000 00000000bfc0f3b4 0000000000000000 0000000000000000<br /> 0000000000000000 0000000000000000 0000000000000000 0000000000000000<br /> 0000000000000000 0000000000000000 0000000000000000 0000000000000000<br /> 0000002500000000 0000000000000000 0000000000000000 802c1a7400000000<br /> 0203bd0080596dc8 0203bd4d69000000 6c61632000000018 5f746567646e6172<br /> 6c616320625f6d6f 5f736e5f6d6f7266 206361323778302b 303d74696e726320<br /> 806a0a38806b0000 806a0a38806b0000 00000000806b0000 80683c58806b0000<br /> ...<br /> Call Trace:<br /> <br /> Code: a082ffff 03e00008 00601021 00001821 10400005 24840001 80820000 24630001<br /> <br /> ---[ end trace 0000000000000000 ]---<br /> Kernel panic - not syncing: Fatal exception in interrupt<br /> <br /> KN04 V2.1k (PC: 0xa0026768, SP: 0x806848e8)<br /> &gt;&gt;<br /> <br /> In this case the pointer in $4 was truncated from 0x980000000203bd00 to<br /> 0x000000000203bd00.<br /> <br /> This may happen when no final console driver has been enabled in the<br /> configuration and consequently the initial console continues being used<br /> late into bootstrap or with an upcoming change that will switch the zs<br /> driver to use a platform device, which in turn will make the console<br /> handover happen only after other kernel threads have already been<br /> started.<br /> <br /> Fix the issue by making the buffer static and initdata, and therefore<br /> placed in the CKSEG0 32-bit compatibility segment, observing that the<br /> console output handler is called with the console lock held, implying<br /> no need for this code to be reentrant. Add an assertion to verify the<br /> buffer actually has been placed in a compatibility segment.

Impacto