Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation

Computing the effects of a TLB invalidation involves looking at
the size of the mapping cached by the TLB. For S1 mappings such as
VNCR, this is deducted from the combination of the base granule size
and the mapping level.

However, this implies that the S1 MMU is *on*. When the MMU is off,
we indicate this with the level being set to a "creative" value of
-127 (S1_MMU_DISABLED).

This ends-up being misinterpreted by pgshift_level_to_ttl() as it
doesn't handle negative levels at all (the level is immediately cast
to a u8 and only the bottom two bits considered), leading to an
invalidation size of 0. Not helpful.

Tidy-up pgshift_level_to_ttl() to handle these negative levels, and
ttl_to_size() to always return SZ_1G when no valid TTL is present.
This allows the removal of open-coded checks for similar situations.

Note that the check for a negative value not explicitely checking for
S1_MMU_DISABLED is deliberate, so that actual negative levels introduced
with LVA2 and D128 can take the same path if we ever support them.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

A flaw in the Linux kernel's arm64 KVM code incorrectly handles an S1 walk level that is set to a negative sentinel value when the MMU is disabled. The level value is cast to an unsigned byte, causing the bit-shift function to interpret the value as zero. Consequently the calculated TLB invalidation size is zero and the TLB entries that should be flushed are left intact. A guest VM that is able to execute code could therefore read or modify the kernel memory or other guests' memory that should have been invalidated, allowing the guest to gain host privileges or interfere with other VMs. The weakness arises from a signed-to-unsigned conversion error and deliberate lack of validation, corresponding to CWE-190.

Affected Systems

All Linux kernels that use the KVM implementation for arm64, irrespective of release version, are potentially affected because the code paths involving the S1_MMU_DISABLED state are part of the default KVM code base. No specific kernel version numbers are cited, so any kernel that has not applied the patch commit that fixes the negative walk level handling remains vulnerable.

Risk and Exploitability

The CVSS score of 9.3 gives this vulnerability critical severity, but the EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis. Because the issue requires the attack surface of a guest VM that can run code inside the hypervisor, the exploitability hinges on having unrestricted code execution within the VM. The vulnerability is not listed in the CISA KEV catalog, suggesting that no publicly known exploits exist yet. Nonetheless, the combination of a high severity score and the capability to potentially read or write protected memory makes this issue a high priority for patching.

Generated by OpenCVE AI on September 20, 2026 at 04:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that contains the KVM patch (the commit identified by 1c9fca34 or any later kernel that incorporates it).
  • If an upgrade cannot be performed immediately, disable the S1_MMU_DISABLED mode in the hypervisor configuration so that the guest cannot engage that code path until the kernel is patched.
  • Monitor KVM and kernel logs for any TLB flush failures or anomalies related to S1 mapping handling, and apply kernel updates as soon as they are available.

Generated by OpenCVE AI on September 20, 2026 at 04:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-195
CWE-20

Thu, 17 Sep 2026 12:15:00 +0000


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
References

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-195
CWE-20

Wed, 16 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB. For S1 mappings such as VNCR, this is deducted from the combination of the base granule size and the mapping level. However, this implies that the S1 MMU is *on*. When the MMU is off, we indicate this with the level being set to a "creative" value of -127 (S1_MMU_DISABLED). This ends-up being misinterpreted by pgshift_level_to_ttl() as it doesn't handle negative levels at all (the level is immediately cast to a u8 and only the bottom two bits considered), leading to an invalidation size of 0. Not helpful. Tidy-up pgshift_level_to_ttl() to handle these negative levels, and ttl_to_size() to always return SZ_1G when no valid TTL is present. This allows the removal of open-coded checks for similar situations. Note that the check for a negative value not explicitely checking for S1_MMU_DISABLED is deliberate, so that actual negative levels introduced with LVA2 and D128 can take the same path if we ever support them.
Title KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T17:07:09.850Z

Reserved: 2026-09-11T19:38:34.765Z

Link: CVE-2026-89775

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T09:17:07.850

Modified: 2026-09-16T18:17:19.027

Link: CVE-2026-89775

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T00:00:00Z

Links: CVE-2026-89775 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound