5.5

CVE-2026-98164

KVM: x86/mmu: Check write tracking in all address spaces

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86/mmu: Check write tracking in all address spaces

kvm_gfn_is_write_tracked() checks only the supplied memslot, but page
tracking is per-address-space and shadow pages are shared across all
address spaces.  With SMM, a GFN can therefore be write-tracked in one
address space and appear untracked through the other.

Check the supplied slot first, then the slot for the other address space.
This ensures all callers honor write tracking regardless of the active
address space.  In particular, it prevents mmu_try_to_unsync_pages() from
marking an upper-level shadow page unsync and eventually triggering the
BUG in pte_list_remove().

[invert direction of the conditional. - Paolo]
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.2 < 6.1.187
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.156
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.108
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.49
Linux ≫ Linux Kernel Version >= 6.19 < 7.1.13
Linux ≫ Linux Kernel Version 7.2 Update rc1
Linux ≫ Linux Kernel Version 7.2 Update rc2
Linux ≫ Linux Kernel Version 7.2 Update rc3
Linux ≫ Linux Kernel Version 7.2 Update rc4
Linux ≫ Linux Kernel Version 7.2 Update rc5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.08
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE-670 Always-Incorrect Control Flow Implementation

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

https://git.kernel.org/stable/c/09aa68552d2542cc6c23edd1568ac265dc5d886f
Patch
https://git.kernel.org/stable/c/0f38453cdb2e17566ccb7c0f3dabd5bd21caca26
Patch
https://git.kernel.org/stable/c/429b6f43b4d8c98988fdca99e02dc156134e3d77
Patch
https://git.kernel.org/stable/c/c0a9bd5fca0b5f2dea32b0fc31350e71e8648112
Patch
https://git.kernel.org/stable/c/d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212a
Patch
https://git.kernel.org/stable/c/ec8fcaf354c1cbb36755d48e9f5a00c9591349e5
Patch