Junglewise Threat Intelligence

CVE-2026-72169: Linux kernel KHO memory alignment integrity issue

CVE-2026-72169 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Kexec HandOver (KHO) feature, which enables live system updates without downtime, failed to properly align scratch memory buffers when using fixed command-line size parameters. This misalignment could result in memory pages being only partially marked as scratch space, potentially causing corruption or undefined behavior during memory allocation and deallocation in critical kernel operations.

Technical details

The vulnerability exists in the KHO (Kexec HandOver) subsystem's scratch_size_update() function within kernel/liveupdate/kexec_handover.c. When scratch sizes are calculated using scratch_scale (a percentage), the code properly rounds up to CMA_MIN_ALIGNMENT_BYTES, but this rounding was not applied to fixed scratch sizes specified via command-line parameters. Since scratch areas are released as MIGRATE_CMA pages, improper alignment can leave pageblocks partially marked as scratch, violating memory management invariants. The fix ensures rounding-up is applied uniformly to both calculation methods. No network or authentication is required; this is a local kernel configuration issue affecting systems using KHO with fixed scratch sizes.

Affected products

  • Linux Linux Kernel Multiple versions from 2.6.11 through 7.2 (see commit history for exact affected range)

Timeline

  • 2026-08-15: disclosed
  • 2026-05-19: patched: Upstream fix committed

References

Related threats