PT-2026-93569 · Linux · Linux Kernel

CVE-2026-89928

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the KVM x86 MMU where the kvm rmap lock() function elides the rmap lock when an empty rmap is observed. The kvm rmap age gfn range() function ignores the returned value and enters for each rmap spte lockless(), which uses rmap get first() to re-read rmap head->val. If a writer populates the rmap between these two reads, the aging path may walk the newly installed rmap without holding the necessary lock. In cases of a KVM RMAP MANY rmap, this allows a walker to follow a pte list desc chain that was not locked. A writer holding mmu lock for write could then free that chain via kmem cache free() while the walk is in progress, resulting in a slab use-after-free. This condition occurs when CONFIG KVM MMU LOCKLESS AGING is enabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89928
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel