CVE-2026-43289
kexec: derive purgatory entry from symbol
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In the Linux kernel, the following vulnerability has been resolved: kexec: derive purgatory entry from symbol kexec_load_purgatory() derives image->start by locating e_entry inside an
SHF_EXECINSTR section. If the purgatory object contains multiple
executable sections with overlapping sh_addr, the entrypoint check can
match more than once and trigger a WARN. Derive the entry section from the purgatory_start symbol when present and
compute image->start from its final placement. Keep the existing e_entry
fallback for purgatories that do not expose the symbol. WARNING: kernel/kexec_file.c:1009 at kexec_load_purgatory+0x395/0x3c0, CPU#10: kexec/1784
Call Trace: <TASK> bzImage64_load+0x133/0xa00 __do_sys_kexec_file_load+0x2b3/0x5c0 do_syscall_64+0x81/0x610 entry_SYSCALL_64_after_hwframe+0x76/0x7e [me@linux.beauty: move helper to avoid forward declaration, per Baoquan]
CVSS Scores
SSVC
- Decision:-
Timeline
- 2026-05-01 CVE Reserved
- 2026-05-08 CVE Published
- 2026-05-12 CVE Updated
- 2026-05-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (15)
| URL | Tag | Source |
|---|---|---|
| https://git.kernel.org/stable/c/f368aed4827bd4276c0e3664fb2cb815a8d7caf3 | Vuln. Introduced | |
| https://git.kernel.org/stable/c/d38e051ec6fd8650b139d9bc4b0b8b261953b263 | Vuln. Introduced | |
| https://git.kernel.org/stable/c/013027918a4efa807409fcb356009c117e4d181a | Vuln. Introduced | |
| https://git.kernel.org/stable/c/8652d44f466ad5772e7d1756e9457046189b0dfc | Vuln. Introduced | |
| https://git.kernel.org/stable/c/4947a0eb7d642b6048559857964966016ef3aa8b | Vuln. Introduced | |
| https://git.kernel.org/stable/c/b16bf76b382810257e3fb6278663a9d131b70197 | Vuln. Introduced | |
| https://git.kernel.org/stable/c/cb1638618545182a01444b2b20a4ed6b9d2a8c8f | Vuln. Introduced |
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.10.185 < 5.10.252 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.10.185 < 5.10.252" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.15.118 < 5.15.202 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.15.118 < 5.15.202" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.1.35 < 6.1.165 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.1.35 < 6.1.165" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.4 < 6.6.128 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.4 < 6.6.128" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.4 < 6.12.75 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.4 < 6.12.75" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.4 < 6.18.16 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.4 < 6.18.16" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.4 < 6.19.6 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.4 < 6.19.6" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.4 < 7.0 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.4 < 7.0" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 4.19.287 Search vendor "Linux" for product "Linux Kernel" and version "4.19.287" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 5.4.248 Search vendor "Linux" for product "Linux Kernel" and version "5.4.248" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 6.3.9 Search vendor "Linux" for product "Linux Kernel" and version "6.3.9" | en |
Affected
| ||||||
