Description
In the Linux kernel, the following vulnerability has been resolved:

LoongArch: KVM: Free init resources if kvm_init() fails

kvm_loongarch_init() calls kvm_loongarch_env_init() to allocate the
per-CPU kvm_context (vmcs) and kvm_loongarch_ops and to register the
perf callbacks, and then calls kvm_init(). If kvm_init() fails its
result is returned directly, but since module_init() does not run the
module_exit() stuff on failure, so kvm_loongarch_env_exit() is never
called and those resources are leaked.

So call kvm_loongarch_env_exit() when kvm_init() fails, matching the
teardown-on-failure pattern used by riscv_kvm_init().
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource exhaustion from leaked kvm_contexts
Action: Patch
AI Analysis

Impact

The mis‑ordered teardown path in the LoongArch KVM driver causes per‑CPU kvm_context structures and associated callbacks to be allocated before the generic kvm_init() routine is called. If kvm_init() fails, the driver never calls kvm_loongarch_env_exit(), leaving those resources allocated and ultimately exhausting kernel memory or other per‑CPU resources. The consequence is a local denial of service through resource depletion, potentially forcing the kernel to use swap or crash if the leak persists. This flaw is a classic resource leak and could be classified as CWE‑401.

Affected Systems

All Linux kernel builds that include the LoongArch KVM module and run LoongArch processors. The vulnerability is present in any kernel configuration where the kvm_loongarch_init() code path is compiled in, regardless of the specific kernel version, until the fix is applied.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low likelihood of exploitation. The bug manifests only when the KVM module is loaded or the kernel is rebooted, so it requires privileged boot or module loading capabilities. Therefore the risk is primarily local and limited to systems that run LoongArch hardware with KVM enabled.

Generated by OpenCVE AI on September 18, 2026 at 07:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the LoongArch KVM initialization fix and reboot the system to activate the corrected code.
  • If an immediate kernel upgrade is not possible, disable the LoongArch KVM module or prevent it from loading during boot to stop the resource leak from occurring.
  • As an additional precaution, rebuild the kernel with LoongArch KVM support disabled (CONFIG_KVM_LOONGARCH=n) if the environment does not require virtualization on that platform.

Generated by OpenCVE AI on September 18, 2026 at 07:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Free init resources if kvm_init() fails kvm_loongarch_init() calls kvm_loongarch_env_init() to allocate the per-CPU kvm_context (vmcs) and kvm_loongarch_ops and to register the perf callbacks, and then calls kvm_init(). If kvm_init() fails its result is returned directly, but since module_init() does not run the module_exit() stuff on failure, so kvm_loongarch_env_exit() is never called and those resources are leaked. So call kvm_loongarch_env_exit() when kvm_init() fails, matching the teardown-on-failure pattern used by riscv_kvm_init().
Title LoongArch: KVM: Free init resources if kvm_init() fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:07.278Z

Reserved: 2026-09-11T19:38:34.774Z

Link: CVE-2026-89909

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:59.917

Modified: 2026-09-16T11:16:59.917

Link: CVE-2026-89909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses

No weakness.