Description
In the Linux kernel, the following vulnerability has been resolved:

kho: fix size calculation in kho_preserved_memory_reserve()

kho_preserved_memory_reserve() calculates the size of a preservation by
doing 1 << (order + PAGE_SHIFT). Since the '1' is a 32-bit integer, it
can only be shifted by 31. That is, it will only work for preservations
up to 2 GiB. Larger preservations will trigger undefined behaviour.

While preservations larger than 2 GiB can't be obtained via folios
currently, they can be obtained via kho_preserve_pages().

For example, memblock reserve_mem uses kho_preserve_pages().
Reservations larger than 2 GiB are valid and will trigger this bug if
properly aligned.

Fix it by using 1UL for shifting.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption or kernel crash due to incorrect size calculation for preserved memory exceeding 2 GiB in Linux kernel
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in the Linux kernel’s kho module. The function kho_preserved_memory_reserve() calculates the size of a left shift on the constant 1: 1 << (order + PAGE_SHIFT). Since the '1' is a 32-bit integer, shifting it more than 31 bits causes undefined behavior. For preserved regions larger than 2 GiB the shift mis‑computes the size, potentially leading to memory corruption or a kernel crash. The flaw is catalogued as CWE‑1335.

Affected Systems

All Linux kernel builds that contain the unpatched kho module are affected. or branch; therefore the impact applies generically to any kernel version that still uses the original calculation. Because the bug can be triggered by allocating preserved memory larger than 2 GiB – for example via kho_preserve_pages() or the memblock reserve_mem API – any system that may request such a reservation is potentially vulnerable. The exact scope depends on the kernel configuration and the ability to request large preserved regions.

Risk and Exploitability

The CVSS score of 4.4 rates the vulnerability as low severity. Its EPSS score is below 1 %, indicating a small chance of exploitation in the wild, and it is not on the CISA KEV list. An attacker requiring local privileged code with kernel‑mode access could trigger the bug by requesting a preserved region that exceeds 2 GiB, which may the kernel. Remote exploitation appears unlikely without kernel‑level privileges.

Generated by OpenCVE AI on September 15, 2026 at 21:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patched kho module.
  • Avoid requesting preserved memory reservations larger than 2 GiB through kho_preserve_pages() or memblock reserve_mem until a patched kernel is deployed.
  • Monitor system logs for abnormal kernel panics or memory corruption messages that could indicate the bug has been triggered, and apply the patch as soon as possible.

Generated by OpenCVE AI on September 15, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1335
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: kho: fix size calculation in kho_preserved_memory_reserve() kho_preserved_memory_reserve() calculates the size of a preservation by doing 1 << (order + PAGE_SHIFT). Since the '1' is a 32-bit integer, it can only be shifted by 31. That is, it will only work for preservations up to 2 GiB. Larger preservations will trigger undefined behaviour. While preservations larger than 2 GiB can't be obtained via folios currently, they can be obtained via kho_preserve_pages(). For example, memblock reserve_mem uses kho_preserve_pages(). Reservations larger than 2 GiB are valid and will trigger this bug if properly aligned. Fix it by using 1UL for shifting.
Title kho: fix size calculation in kho_preserved_memory_reserve()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:44:38.078Z

Reserved: 2026-09-11T19:38:34.726Z

Link: CVE-2026-89568

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:40.810

Modified: 2026-09-11T20:19:40.810

Link: CVE-2026-89568

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:38Z

Links: CVE-2026-89568 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses
  • CWE-1335

    Incorrect Bitwise Shift of Integer