-

CVE-2026-89917

KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping

While VNCR TLB invalidation always occurs under the MMU lock,
vcpu_put() doesn't, while it unmaps the VNCR page.

The problem is that the invalidation evaluates vncr_tlb::cpu to
decide whether an unmapping needs to take place (cpu != -1) before
performing it. On the other hand, this_cpu_reset_vncr_fixmap()
unconditionally unmaps if L1_VNCR_MAPPED is set.

These two obviously can race, with a TOCTOU pattern on the TLBI
path, and a BUG_ON() on the vcpu_put() path. And the two can end-up
calling vncr_fixmap(-1), with extra lethal effects.

Move the reset of vncr_tlb::cpu to -1 to a common function, and make
this update atomic so that only a single thread can reset the field
and perform the corresponding unmap. The vcpu_put() still need to
unconditionally unmap the current VNCR to close another ugly race.

Finally, the assignment of vncr_tlb::cpu is moved to be kept in sync
with the actual mapping, similar to L1_VNCR_MAPPED being set.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7270cc9157f474dfc46750a34c9d7defc686b2eb
Version < 5cbd8761d001c11ada73b1753d772c4745a70e72
Status affected
Version 7270cc9157f474dfc46750a34c9d7defc686b2eb
Version < 9065c1261f8a05c6a7a2d90048c7c0665ab2896d
Status affected
Version 7270cc9157f474dfc46750a34c9d7defc686b2eb
Version < 38640bc32be3fcf9526d477155bc19d3f146231f
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.16
Status affected
Version 0
Version < 6.16
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5cbd8761d001c11ada73b1753d772c4745a70e72
https://git.kernel.org/stable/c/9065c1261f8a05c6a7a2d90048c7c0665ab2896d
https://git.kernel.org/stable/c/38640bc32be3fcf9526d477155bc19d3f146231f