Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables

vgic_v3_save_pending_tables() iterates dist->lpi_xa using xa_for_each()
and dereferences the returned struct vgic_irq in the loop body without
holding a reference on the LPI.

The xarray iterator only provides temporary RCU coverage while looking up
the current entry. That is not sufficient for this loop body, which reads
fields from struct vgic_irq and performs guest memory accesses before the
iteration completes.

A concurrent path can trigger this race: the irqfd cached injection path
(vgic_its_inject_cached_translation) obtains a transient LPI reference
via vgic_its_check_cache() without holding kvm->lock, vcpu->mutex,
config_lock, or its_lock. If guest ITS DISCARD then drops the cache and
ITE references under its_lock, the transient inject reference may become
the final one. When vgic_put_irq() drops it, the LPI is erased from
lpi_xa and freed via kfree_rcu(). Meanwhile, vgic_v3_save_pending_tables()
may still hold a stale pointer obtained from the xarray iterator and
dereference it after the RCU grace period completes.

Fix this by re-fetching each iterated LPI via vgic_get_irq(), which takes
a stable reference, and dropping it with vgic_put_irq() on all paths.
This matches the pattern already used by other lpi_xa iterators in the
vgic ITS code.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel's KVM arm64 VGIC v3 implementation, where vgic_v3_save_pending_tables() iterates over the LPI xarray and dereferences a struct vgic_irq without taking a stable reference. This race opens a use‑after‑free window that can corrupt kernel memory and, if exploited, can lead to arbitrary code execution with host kernel privileges. The vulnerability is a classic use‑after‑free and race condition that sits entirely in kernel space, meaning any malicious guest can target it with privileged guest drivers.

Affected Systems

Linux kernels running on arm64 with KVM and the virtual generic interrupt controller (vgic v3) are impacted. The issue is present in all kernel versions that contain the flawed vgic_v3_save_pending_tables() logic, regardless of distribution, until the fix is applied.

Risk and Exploitability

The CVSS score is 8.8, indicating a high severity. However, the EPSS score is below 1 %, showing that, as of this analysis, exploitation is not widely observed. The vulnerability is not listed in the CISA KEV catalog. The attack vector is internal to the hypervisor: a guest that can trigger an ITS discard or a cached injection path can race with the host’s table save routine, potentially leading to kernel memory corruption. Users running virtual machines on affected hosts should consider this risk high if they cannot immediately update the kernel.

Generated by OpenCVE AI on September 18, 2026 at 03:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that contains the commit which re‑fetches each iterated LPI via vgic_get_irq() to avoid the user‑after‑free race.
  • If a kernel upgrade is not immediately possible, configure KVM to disable or limit LPI injection paths that can race with table saving—e.g., by disabling ITS dirty updates or using guest capabilities restrictions.
  • Monitor kernel logs for unexpected crashes or memory corruption, and enable kernel hardening options such as CONFIG_RCU_STRICT_GRAIN and CONFIG_DEBUG_KERNEL to surface any residual races.

Generated by OpenCVE AI on September 18, 2026 at 03:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables vgic_v3_save_pending_tables() iterates dist->lpi_xa using xa_for_each() and dereferences the returned struct vgic_irq in the loop body without holding a reference on the LPI. The xarray iterator only provides temporary RCU coverage while looking up the current entry. That is not sufficient for this loop body, which reads fields from struct vgic_irq and performs guest memory accesses before the iteration completes. A concurrent path can trigger this race: the irqfd cached injection path (vgic_its_inject_cached_translation) obtains a transient LPI reference via vgic_its_check_cache() without holding kvm->lock, vcpu->mutex, config_lock, or its_lock. If guest ITS DISCARD then drops the cache and ITE references under its_lock, the transient inject reference may become the final one. When vgic_put_irq() drops it, the LPI is erased from lpi_xa and freed via kfree_rcu(). Meanwhile, vgic_v3_save_pending_tables() may still hold a stale pointer obtained from the xarray iterator and dereference it after the RCU grace period completes. Fix this by re-fetching each iterated LPI via vgic_get_irq(), which takes a stable reference, and dropping it with vgic_put_irq() on all paths. This matches the pattern already used by other lpi_xa iterators in the vgic ITS code.
Title KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:16.550Z

Reserved: 2026-09-11T19:38:34.774Z

Link: CVE-2026-89913

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:00.333

Modified: 2026-09-17T10:17:04.810

Link: CVE-2026-89913

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:45:01Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free