PT-2026-93381 · Linux · Linux Kernel

CVE-2026-89775

·

Published

2026-09-16

·

Updated

2026-09-28

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 6.17 through 6.18.50 Linux kernel versions 7.0 through 7.2.4
Description A flaw in the Linux kernel's KVM virtualization code for ARM64 processors can allow a guest virtual machine to escape to the host system. The issue occurs when nested virtualization is enabled on Armv8.4 hardware with FEAT NV2. A failure in the VNCR TLB (Translation Lookaside Buffer) invalidation logic occurs because the pgshift level to ttl() function does not handle negative levels, such as the value -127 used when the S1 MMU (Memory Management Unit) is disabled. This results in an invalidation size of 0, causing the system to skip clearing stale entries from the processor's address cache.
Consequently, a page of host kernel memory that has been freed remains mapped and writable, creating a use-after-free condition. A malicious guest can use this to read and write host kernel memory 64 bits at a time, which can be leveraged to execute arbitrary code on the host machine. This vulnerability is only reachable on hosts booted with the kvm-arm.mode=nested parameter.
Recommendations Update Linux kernel to version 6.18.51. Update Linux kernel to version 7.2.5. Disable nested virtualization on ARM64 KVM hosts by ensuring the kvm-arm.mode=nested boot parameter is not used if the feature is not strictly required.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:72624
BDU:2026-15576
CVE-2026-89775
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel