PT-2026-93554 · Linux · Linux Kernel
CVE-2026-89913
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
In the Linux kernel KVM arm64 vgic-v3 component, the
vgic v3 save pending tables() function iterates through dist->lpi xa using xa for each() and dereferences the returned struct vgic irq without holding a proper reference to the LPI (Locality-specific Peripheral Interrupt). The xarray iterator provides only temporary RCU (Read-Copy-Update) coverage, which is insufficient for the loop body that reads fields from struct vgic irq and performs guest memory accesses.A race condition occurs when the irqfd cached injection path
vgic its inject cached translation() obtains a transient LPI reference via vgic its check cache() without holding necessary locks. If a guest ITS DISCARD operation drops the cache and ITE references, the transient reference may become the final one. Once vgic put irq() drops this reference, the LPI is erased from lpi xa and freed via kfree rcu(). Consequently, vgic v3 save pending tables() may dereference a stale pointer after the RCU grace period ends.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel