PT-2026-106612 · Linux · Linux
CVE-2026-98283
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
KVM: PPC: Book3S HV: fix use-after-free in kvmhv emulate tlbie all lpid()
kvmhv emulate tlbie all lpid() iterates the nested-guest IDR and drops
mmu lock before calling kvmhv emulate tlbie lpid(), but does not hold a
reference on the kvm nested guest pointer obtained from the IDR. A
concurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race
through kvmhv flush nested() -> kvmhv remove nested() -> idr remove /
--refcnt -> kvmhv release nested() -> kfree(gp) in that window, leaving
the iterating vCPU with a dangling pointer. The subsequent
mutex lock(&gp->tlb lock) and accesses to gp->shadow pgtable,
gp->shadow lpid and gp->l1 host all touch freed memory. The free path
is fully L1-controlled.
Fix this by incrementing gp->refcnt inside the loop before dropping
mmu lock, mirroring what kvmhv get nested() does, and releasing the
reference with kvmhv put nested() after the per-guest work completes.
This is the same get/put discipline already used at every other
call site that drops mmu lock while holding a nested-guest pointer.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux