PT-2026-93557 · Linux · Linux Kernel
CVE-2026-89916
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
9.3
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the KVM arm64 implementation where VNCR (Virtual Non-Global Control Register) TLB invalidation does not correctly participate in the MMU invalidation retry mechanism. This can lead to a race condition where one vCPU translates a VNCR and, before it can acquire the MMU lock to insert the TLB entry, another vCPU updates the S1 Page Tables (PTs) with an invalid entry and issues a TLBI S1E2 for that virtual address. Consequently, the first vCPU may insert an invalid TLB entry. The fix involves extending the
invalidate vncr va() function to update the mmu invalidate seq counter, ensuring the fault is replayed when the context changes.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel