{"id":82514,"date":"2026-07-24T19:01:19","date_gmt":"2026-07-24T15:31:19","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-64252-mips-dec-prevent-initial-console-buffer-from-landing-in-xkphys\/"},"modified":"2026-07-24T19:01:19","modified_gmt":"2026-07-24T15:31:19","slug":"cve-2026-64252-mips-dec-prevent-initial-console-buffer-from-landing-in-xkphys","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-64252-mips-dec-prevent-initial-console-buffer-from-landing-in-xkphys\/","title":{"rendered":"CVE-2026-64252 &#8211; MIPS: DEC: Prevent initial console buffer from landing in XKPHYS"},"content":{"rendered":"<p>CVE ID :CVE-2026-64252<\/p>\n<p>  Published : July 24, 2026, 3:31 p.m. | 19\u00a0minutes ago<\/p>\n<p>  Description :In the Linux kernel, the following vulnerability has been resolved:<\/p>\n<p>MIPS: DEC: Prevent initial console buffer from landing in XKPHYS<\/p>\n<p>In 64-bit configurations calling the initial console output handler from<br \/>\na kernel thread other than the initial one will result in a situation<br \/>\nwhere the stack has been placed in the XKPHYS 64-bit memory segment and<br \/>\nconsequently so has been the buffer allocated there that is used as the<br \/>\nargument corresponding to the `%s&#8217; output conversion specifier for the<br \/>\nfirmware&#8217;s printf() entry point.<\/p>\n<p>This 64-bit address will then be truncated by 32-bit firmware, resulting<br \/>\nin an attempt to access the wrong memory location, which in turn will<br \/>\ncause all kinds of unpredictable behaviour, such as a kernel crash:<\/p>\n<p>  Console: colour dummy device 160&#215;64<br \/>\n  Calibrating delay loop&#8230; 49.36 BogoMIPS (lpj=192512)<br \/>\n  pid_max: default: 32768 minimum: 301<br \/>\n  CPU 0 Unable to handle kernel paging request at virtual address 000000000203bd00, epc == ffffffffbfc08364, ra == ffffffffbfc08800<br \/>\n  Oops[#1]:<br \/>\n  CPU: 0 PID: 0 Comm: swapper Not tainted 5.18.0-rc2-00254-gfb649bda6f56-dirty #121<br \/>\n  $ 0   : 0000000000000000 0000000000000001 0000000000000023 ffffffff80684ba0<br \/>\n  $ 4   : 000000000203bd00 ffffffffbfc0f3b4 ffffffffffffffff 0000000000000073<br \/>\n  $ 8   : 0a303d7469000000 0000000000000000 0000000000000073 ffffffffbfc0f473<br \/>\n  $12   : 0000000000000002 0000000000000000 ffffffff80684c1c 0000000000000000<br \/>\n  $16   : 0000000000000000 ffffffff80596dc9 0000000000000000 ffffffffbfc09240<br \/>\n  $20   : ffffffff80684c40 ffffffffbfc0f400 000000000000002d 000000000000002b<br \/>\n  $24   : ffffffffffffffbf 000000000203bd00<br \/>\n  $28   : ffffffff805f0000 ffffffff80684b58 0000000000000030 ffffffffbfc08800<br \/>\n  Hi    : 0000000000000000<br \/>\n  Lo    : 0000000000000aa8<br \/>\n  epc   : ffffffffbfc08364 0xffffffffbfc08364<br \/>\n  ra    : ffffffffbfc08800 0xffffffffbfc08800<br \/>\n  Status: 140120e2        KX SX UX KERNEL EXL<br \/>\n  Cause : 00000008 (ExcCode 02)<br \/>\n  BadVA : 000000000203bd00<br \/>\n  PrId  : 00000430 (R4000SC)<br \/>\n  Modules linked in:<br \/>\n  Process swapper (pid: 0, threadinfo=(____ptrval____), task=(____ptrval____), tls=0000000000000000)<br \/>\n  Stack : 0000000000000000 0000000000000000 0000000000000000 0000004d0000004d<br \/>\n          80684cc0806a2a40 80596dc80000004d 8061000000000000 bfc0850c80684c38<br \/>\n          0000000000000000 000000000203bd00 0000000000000000 0000000000000000<br \/>\n          0000000000000000 00000000bfc0f3b4 0000000000000000 0000000000000000<br \/>\n          0000000000000000 0000000000000000 0000000000000000 0000000000000000<br \/>\n          0000000000000000 0000000000000000 0000000000000000 0000000000000000<br \/>\n          0000002500000000 0000000000000000 0000000000000000 802c1a7400000000<br \/>\n          0203bd0080596dc8 0203bd4d69000000 6c61632000000018 5f746567646e6172<br \/>\n          6c616320625f6d6f 5f736e5f6d6f7266 206361323778302b 303d74696e726320<br \/>\n          806a0a38806b0000 806a0a38806b0000 00000000806b0000 80683c58806b0000<br \/>\n          &#8230;<br \/>\n  Call Trace:<\/p>\n<p>  Code: a082ffff  03e00008  00601021  00001821  10400005  24840001  80820000  24630001<\/p>\n<p>  &#8212;[ end trace 0000000000000000 ]&#8212;<br \/>\n  Kernel panic &#8211; not syncing: Fatal exception in interrupt<\/p>\n<p>  KN04 V2.1k    (PC: 0xa0026768, SP: 0x806848e8)<br \/>\n  &gt;&gt;<\/p>\n<p>In this case the pointer in $4 was truncated from 0x980000000203bd00 to<br \/>\n0x000000000203bd00.<\/p>\n<p>This may happen when no final console driver has been enabled in the<br \/>\nconfiguration and consequently the initial console continues being used<br \/>\nlate into bootstrap or with an upcoming change that will switch the zs<br \/>\ndriver to use a platform device, which in turn will make the console<br \/>\nhandover happen only after other kernel threads have already been<br \/>\nstarted.<\/p>\n<p>Fix the issue by making the buffer static and initdata, and therefore<br \/>\nplaced in the CKSEG0 32-bit compatibility segment, observing that the<br \/>\nconsole output handler is called with the console lock held, implying<br \/>\nno need for this code to be reentrant.  Add an assertion to verify the<br \/>\nbuffer actually has been placed in a compatibility segment.<\/p>\n<p>  Severity: 0.0 | NA<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-64252 Published : July 24, 2026, 3:31 p.m. | 19\u00a0minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: MIPS: DEC: Prevent initial console buffer from landing in XKPHYS In 64-bit configurations calling the initial console output handler from a kernel thread other than the initial one will result in &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-82514","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/82514","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=82514"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/82514\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=82514"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=82514"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=82514"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}