Page MenuHomeFreeBSD

kexec: Disallow kexec_load if securelevel > 0
ClosedPublic

Authored by jhibbits on Apr 22 2026, 3:52 PM.
Tags
None
Referenced Files
Unknown Object (File)
Fri, Oct 2, 10:45 PM
Unknown Object (File)
Thu, Oct 1, 11:06 AM
Unknown Object (File)
Wed, Sep 30, 12:09 PM
Unknown Object (File)
Wed, Sep 30, 10:46 AM
Unknown Object (File)
Tue, Sep 29, 10:22 PM
Unknown Object (File)
Tue, Sep 29, 5:31 PM
Unknown Object (File)
Tue, Sep 29, 12:01 PM
Unknown Object (File)
Tue, Sep 29, 3:33 AM
Subscribers

Details

Summary

kexec_load() + reboot is intended to be equivalent to a system reboot.
However kexec_load() can load arbitrary data as the target kernel,
leading to execution of arbitrary code, even though it's effectively in
a new context. Rather than being equivalent to a system reboot, it's
also equivalent to kldload(), which loads arbitrary code into the
running kernel. Since kldload() is blocked at securelevel 1, also block
kexec_load().

Reported by: markj
Fixes: e02c57ff3 ("kern: Introduce kexec system feature (MI)")
MFC after: 2 weeks
Sponsored by: Hewlett Packard Enterprise

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 72448
Build 69331: arc lint + arc unit

Event Timeline

MFC after: 2 weeks

It looks like kexec was never MFCed?

This revision is now accepted and ready to land.Apr 22 2026, 4:05 PM

MFC after: 2 weeks

It looks like kexec was never MFCed?

Oops, I thought I had gotten kexec_load in just before stable/15 branched, but guess not. No need to MFC, then.