Why Your Linux Kernel Starts With 'MZ' (Yes, the DOS/PE One)

Every command and hex dump in this post was run live on this machine (uname -r: 7.2.4-arch1-2) against its real /boot/vmlinuz-linux. Nothing here is a mockup — you can reproduce every byte on your own box.

|=—[ TL;DR ]

Your Linux kernel image (/boot/vmlinuz-*) starts with the two bytes 4D 5A — "MZ" — the ancient MS-DOS executable magic number, followed a little further in by a real "PE\0\0" (COFF) header with Subsystem = IMAGE_SUBSYSTEM_EFI_APPLICATION. This is not a coincidence, a joke, or legacy cruft nobody bothered to remove. It’s required by the UEFI specification: UEFI firmware only knows how to load and execute PE32+ binaries. To let a UEFI system boot Linux with zero extra bootloader code, the kernel’s boot header was made to also be a valid PE/COFF executable — while simultaneously remaining a valid legacy BIOS boot sector for machines that don’t have UEFI at all. Same bytes, two boot protocols.