Impact
A logic flaw in the Linux kernel’s kexec implementation allows an attacker to cause critical memory truncation when overlapping memory ranges are merged. The bug, arising from incorrect comparison and unconditional overwriting of range boundaries, can remove valid memory fragments from the exclude list enabling a crash kernel to overwrite active memory. This results in data corruption or system crashes. The flaw does not involve arbitrary code execution but enables a hostile kernel image to access protected memory regions.
Affected Systems
Linux kernel operating on PowerPC architectures that implement the kexec_file subsystem. The issue exists in all kernel versions that have not been patched with the commit series linked in the advisory; affected users are those running vulnerable kernel releases before the fix was merged.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (<1%), and the vulnerability is not listed in the CISA KEV catalog. The attack requires the ability to load a crash kernel image with a crafted memory range list, which typically necessitates local system access or a path that can invoke kexec. The severity is tied to the kernel’s capability to achieve memory corruption, potentially leading to privilege escalation or denial of service. No CVSS score is provided, but the impact leads to significant integrity and availability risks if exploited.
OpenCVE Enrichment
Debian DLA
Debian DSA