Description
In the Linux kernel, the following vulnerability has been resolved:

LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY

kvm_arch_prepare_memory_region() computes new->arch.flags, i.e. whether
a memslot is KVM_MEM_HUGEPAGE_CAPABLE or KVM_MEM_HUGEPAGE_INCAPABLE,
only for KVM_MR_CREATE and KVM_MR_MOVE, and returns early for every
other change. But the generic code allocates a zeroed memslot for every
change and never copies old->arch, so after a KVM_MR_FLAGS_ONLY update,
e.g. toggling KVM_MEM_LOG_DIRTY_PAGES for live migration, the active
memslot has arch.flags == 0.

With both flags clear, fault_supports_huge_mapping() falls through to
the alignment check on the HVA range alone, which no longer verifies
that the GPA and HVA have the same offset within a PMD. A memslot that
was marked KVM_MEM_HUGEPAGE_INCAPABLE because of a GPA/HVA offset
mismatch can then be mapped with PMD entries on read faults, and since
kvm_map_page() aligns the gfn and the pfn independently, the guest ends
up accessing the wrong host pages, exactly the "d -> f, e -> g" case
described in the comment above the check.

Carry the arch flags over from the old memslot for KVM_MR_FLAGS_ONLY,
as the GPA, HVA and size are guaranteed to be unchanged for that case.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation / Arbitrary Host Memory Access
Action: Patch ASAP
AI Analysis

Impact

The bug occurs in the Linux kernel’s LoongArch KVM code when the memory region flags are changed with the KVM_MR_FLAGS_ONLY operation. The kernel fails to copy architecture‑specific flags from the old memory slot into the new one, causing the arch.flags to be zero. This missing flag means that huge‑page support checks are bypassed, allowing the kernel to map guest pages to incorrect host pages during read faults. An attacker who can make the KVM memory region flags change—for example by toggling KVM_MEM_LOG_DIRTY_PAGES during live migration—can force the guest to read or write user‑space or kernel memory outside its allocated region, potentially leading to privilege escalation or arbitrary code execution on the host.

Affected Systems

Affected systems are all Linux kernel builds running on LoongArch CPUs that use the KVM hypervisor. The vulnerability manifests only in kernels that have not received the patch changes referenced in the provided kernel commit URLs. No specific kernel version range is listed, so any current release that has not yet been updated is vulnerable.

Risk and Exploitability

The CVSS score is 8.8, showing a high‑severity flaw, but the EPSS score is below 1 % and the vulnerability is not yet listed in the CISA KEV catalog, indicating that exploitation is unlikely but still possible. The attack requires privileged access to the KVM configuration or the ability to trigger a KVM_MR_FLAGS_ONLY operation, which is typically available only to the host administrator or trusted virtual machine manager processes. As a result, the risk is primarily to administrators or attackers who can compromise the host, rather than to end‑user guests.

Generated by OpenCVE AI on September 18, 2026 at 03:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that contains the commit(s) referenced in the advisory and reboot to load the patched kernel.
  • Reboot or restart the KVM service so that all memory slots are reinitialized under the new kernel code.
  • As an interim measure, avoid performing KVM_MR_FLAGS_ONLY operations such as toggling KVM_MEM_LOG_DIRTY_PAGES or live migration until the patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 03:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-269

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY kvm_arch_prepare_memory_region() computes new->arch.flags, i.e. whether a memslot is KVM_MEM_HUGEPAGE_CAPABLE or KVM_MEM_HUGEPAGE_INCAPABLE, only for KVM_MR_CREATE and KVM_MR_MOVE, and returns early for every other change. But the generic code allocates a zeroed memslot for every change and never copies old->arch, so after a KVM_MR_FLAGS_ONLY update, e.g. toggling KVM_MEM_LOG_DIRTY_PAGES for live migration, the active memslot has arch.flags == 0. With both flags clear, fault_supports_huge_mapping() falls through to the alignment check on the HVA range alone, which no longer verifies that the GPA and HVA have the same offset within a PMD. A memslot that was marked KVM_MEM_HUGEPAGE_INCAPABLE because of a GPA/HVA offset mismatch can then be mapped with PMD entries on read faults, and since kvm_map_page() aligns the gfn and the pfn independently, the guest ends up accessing the wrong host pages, exactly the "d -> f, e -> g" case described in the comment above the check. Carry the arch flags over from the old memslot for KVM_MR_FLAGS_ONLY, as the GPA, HVA and size are guaranteed to be unchanged for that case.
Title LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:58.684Z

Reserved: 2026-09-11T19:38:34.774Z

Link: CVE-2026-89908

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:59.807

Modified: 2026-09-16T15:18:17.050

Link: CVE-2026-89908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:45:01Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-269

    Improper Privilege Management