Executive brief
The Linux kernel's LoongArch architecture code contains a flaw in kexec (kernel execution) command line processing where kernel code incorrectly dereferences a user-space memory pointer without proper address space verification. An attacker with privileges to load a kexec image could exploit this to trigger undefined behavior or potentially cause a kernel panic, disrupting system availability or enabling privilege escalation.
Technical details
The vulnerability is a pointer dereference vulnerability in arch/loongarch/kernel/machine_kexec.c. In the kexec_load(2) syscall path (file_mode == 0), the code passes user-space segment buffers directly to strncmp() through an incorrect cast to kernel-space pointers without using copy_from_user(). This violates kernel address space rules and is flagged by the sparse static analyzer. The fix copies marker-sized prefixes into an on-stack buffer with copy_from_user() before comparison, properly handling user-space access and faulting segments. Attack precondition is capability to invoke kexec_load(2), typically requiring CAP_SYS_BOOT or similar privileges.
Affected products
- Linux Linux kernel LoongArch architecture; patched upstream commit 485ed44db5694d8d2e5027f63ad608e705286f30
Timeline
- 2026-08-12: disclosed: CVE-2026-68435 published
- 2026-07-23: patched: Fix commit 485ed44db5694d8d2e5027f63ad608e705286f30