5.5
CVE-2026-98164
- EPSS 0.19%
- Veröffentlicht 29.09.2026 13:17:53
- Zuletzt bearbeitet 07.10.2026 07:17:03
- Erkennungen
KVM: x86/mmu: Check write tracking in all address spaces
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are shared across all address spaces. With SMM, a GFN can therefore be write-tracked in one address space and appear untracked through the other. Check the supplied slot first, then the slot for the other address space. This ensures all callers honor write tracking regardless of the active address space. In particular, it prevents mmu_try_to_unsync_pages() from marking an upper-level shadow page unsync and eventually triggering the BUG in pte_list_remove(). [invert direction of the conditional. - Paolo]
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.2 < 6.1.187
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.156
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.108
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.49
Linux ≫ Linux Kernel Version >= 6.19 < 7.1.13
Linux ≫ Linux Kernel Version 7.2 Update rc1
Linux ≫ Linux Kernel Version 7.2 Update rc2
Linux ≫ Linux Kernel Version 7.2 Update rc3
Linux ≫ Linux Kernel Version 7.2 Update rc4
Linux ≫ Linux Kernel Version 7.2 Update rc5
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.08 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
|
CWE-670 Always-Incorrect Control Flow Implementation
The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.
https://git.kernel.org/stable/c/09aa68552d2542cc6c23edd1568ac265dc5d886f
https://git.kernel.org/stable/c/0f38453cdb2e17566ccb7c0f3dabd5bd21caca26
https://git.kernel.org/stable/c/429b6f43b4d8c98988fdca99e02dc156134e3d77
https://git.kernel.org/stable/c/c0a9bd5fca0b5f2dea32b0fc31350e71e8648112
https://git.kernel.org/stable/c/d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212a
https://git.kernel.org/stable/c/ec8fcaf354c1cbb36755d48e9f5a00c9591349e5