๐Ÿ” CVE Alert

CVE-2026-68435

UNKNOWN 0.0

LoongArch: Fix address space mismatch in kexec command line lookup

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix address space mismatch in kexec command line lookup When searching the loaded segments for the "kexec" command line marker, the kexec_load(2) path (file_mode == 0) passes the user-space segment buffer straight to strncmp() through a bogus (char __user *) cast. This dereferences a user pointer in kernel context, which is wrong and is flagged by sparse: arch/loongarch/kernel/machine_kexec.c:84:51: sparse: incorrect type in argument 2 (different address spaces) @@ expected char const * @@ got char [noderef] __user * Here copy the marker-sized prefix of each segment into a small on-stack buffer with copy_from_user() before comparing, and skip segments that fault. The subsequent copy_from_user() that stages the full command line into the safe area is left unchanged.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
4a03b2ac06a5bcae29371866d9d11f5bfd4c9188 < a94d6726ec8680a2b0c453fc782a543f68a1ea06 4a03b2ac06a5bcae29371866d9d11f5bfd4c9188 < 7a54e0cbaad4a5a09e7cc7a4f05d181048e98ca7 4a03b2ac06a5bcae29371866d9d11f5bfd4c9188 < 485ed44db5694d8d2e5027f63ad608e705286f30
Linux / Linux
6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a94d6726ec8680a2b0c453fc782a543f68a1ea06 git.kernel.org: https://git.kernel.org/stable/c/7a54e0cbaad4a5a09e7cc7a4f05d181048e98ca7 git.kernel.org: https://git.kernel.org/stable/c/485ed44db5694d8d2e5027f63ad608e705286f30