Description
In the Linux kernel, the following vulnerability has been resolved:

liveupdate: validate session type before performing operation

The sessions ioctls are not applicable to all session types. PRESERVE_FD
is only applicable to outgoing sessions. RETRIEVE_FD and FINISH are only
valid for incoming session. Calling a incoming ioctl on an outgoing
session is invalid and can cause file handlers to run into unexpected
errors.

For example, a user can create a (outgoing) session, preserve a memfd,
and then immediately do a retrieve without doing a kexec in between.
This would result in memfd's retrieve handler to run. The handlers
expects to be called from a post-kexec context, and will try to do a
kho_restore_vmalloc() or kho_restore_folio() to try and restore memory.

KHO catches this (thanks to KHO_PAGE_MAGIC) and returns an error, but
since this is considered an internal error and KHO throws out a bunch of
WARN()s.

Associate a type with each ioctl op and validate the type in
luo_session_ioctl() before dispatching the ioctl handler to make sure
the op is being called for the right session type.
Published: 2026-08-15
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when a user issues a session ioctl that does not match the session type. The liveupdate module does not validate the session type before dispatching the handler, causing the handler to run in an inappropriate context. Calls such as RETRIEVE_FD on an outgoing session trigger recovery code that expects a post‑kexec environment. This mismatch leads to internal errors and a cascade of WARN() messages produced by the kernel, disrupting normal operation rather than enabling code execution or privilege escalation.

Affected Systems

The affected product is the Linux kernel. No specific kernel version or patch level is listed in the CNA data, but the issue exists in all builds that contain the liveupdate support path referenced in the kernel source. Users running Linux kernel versions prior to the commit that introduced the type validation are susceptible.

Risk and Exploitability

The CVSS and EPSS scores are not provided, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires an attacker to have access to privileged ioctl interfaces, typically available to the kernel, which limits its exploitability to local, privileged or vulnerable user accounts that can open the liveupdate device. While the risk is primarily a service disruption and generate kernel warnings, it does not lead to remote code execution or data exposure. The lack of EPSS data and KEV listing suggests no widespread exploitation has been observed.

Generated by OpenCVE AI on August 15, 2026 at 08:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a kernel release that includes the commit adding session type validation for liveupdate ioctls
  • Verify that the liveupdate module is compiled and loaded after the patch
  • Reboot the system to apply the kernel changes and ensure the updated liveupdate module is in use

Generated by OpenCVE AI on August 15, 2026 at 08:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 15 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Linux kernel
Vendors & Products Linux kernel

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: liveupdate: validate session type before performing operation The sessions ioctls are not applicable to all session types. PRESERVE_FD is only applicable to outgoing sessions. RETRIEVE_FD and FINISH are only valid for incoming session. Calling a incoming ioctl on an outgoing session is invalid and can cause file handlers to run into unexpected errors. For example, a user can create a (outgoing) session, preserve a memfd, and then immediately do a retrieve without doing a kexec in between. This would result in memfd's retrieve handler to run. The handlers expects to be called from a post-kexec context, and will try to do a kho_restore_vmalloc() or kho_restore_folio() to try and restore memory. KHO catches this (thanks to KHO_PAGE_MAGIC) and returns an error, but since this is considered an internal error and KHO throws out a bunch of WARN()s. Associate a type with each ioctl op and validate the type in luo_session_ioctl() before dispatching the ioctl handler to make sure the op is being called for the right session type.
Title liveupdate: validate session type before performing operation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Kernel Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:51:16.745Z

Reserved: 2026-07-30T09:28:09.395Z

Link: CVE-2026-68455

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:17:17.160

Modified: 2026-08-15T06:17:17.160

Link: CVE-2026-68455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T08:15:04Z

Weaknesses