Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Sign-extend VA for range-based TLBI invalidation

When the decode_range_tlbi() helper was moved to be used for S1 TLBIs,
the required sign extension was omitted. Add it.

As a result, special care must be taken to not overflow PA bits when
this is used for S2 invalidation.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a missing sign extension in the KVM arm64 code path used for range‑based TLB invalidation. Because the virtual address is not sign‑extended before converting it to a PA during an S2 TLBI, the translation can overflow the PA bits. The consequence is that an attacker can cause the hypervisor to invalidate or modify memory at an unintended address, potentially corrupting host memory or breaking isolation between virtual machines. In the worst case, this attack can lead to privilege escalation from a guest VM to the host or denial of service for all VMs.

Affected Systems

Affected systems are Linux kernels that include the KVM module for the arm64 architecture. No exact kernel version range is supplied, but any kernel that uses the KVM arm64 range‑based TLBI code prior to the commit that added the sign extension is vulnerable. This applies to servers or devices running Linux with KVM virtualization on ARM64 CPUs.

Risk and Exploitability

The CVSS score of 9.3 indicates a high‑severity condition. The EPSS score is below 1 %, suggesting a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, the vulnerability remains exploitable locally on a host that runs vulnerable KVM, and an attacker would benefit from control over a guest VM. The required conditions for exploitation are likely to be a privileged guest or a trusted application that can trigger S2 TLBI with an arbitrary address, and the attack vector is inferred to be local to the host.

Generated by OpenCVE AI on September 18, 2026 at 03:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel patch that resolves the missing sign extension for TLBI invalidation (commit 2393470085649f0b973ecceb26fe8fc71edde0c1).
  • Reboot the system after the kernel update to apply the changes and ensure that all virtualization services are restarted.
  • If the patch cannot be applied immediately, restrict or disable KVM on arm64 for untrusted guests until the fix is available.

Generated by OpenCVE AI on September 18, 2026 at 03:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for range-based TLBI invalidation When the decode_range_tlbi() helper was moved to be used for S1 TLBIs, the required sign extension was omitted. Add it. As a result, special care must be taken to not overflow PA bits when this is used for S2 invalidation.
Title KVM: arm64: Sign-extend VA for range-based TLBI invalidation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:06.342Z

Reserved: 2026-09-11T19:38:34.774Z

Link: CVE-2026-89914

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:00.443

Modified: 2026-09-16T15:18:17.647

Link: CVE-2026-89914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:45:01Z

Weaknesses