PT-2026-106578 · Linux · Linux

CVE-2026-98249

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
arm64: hibernate: pass HVC SET VECTORS args to the resume hvc
swsusp arch suspend exit() reinstalls the restored kernel's hyp stub vectors with an hvc, but never passes the arguments. x0 is not set to HVC SET VECTORS and x1 is not set to the vector address, so the stub dispatch falls through and returns without writing vbar el2. EL2 is left pointing at the trans pgd copy of the vectors, a page that swsusp free() releases right after resume.
Set the arguments up the same way hyp set vectors() does.
Without this fix, Vladimir was able to trigger a hang when resuming from hibernation with CONFIG PAGE POISONING=y and page poison=on.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98249

Affected Products

Linux