Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Remove VM-wide VNCR mapping counter

The global VNCR mapping counter is used to decide whether an L1
provided VNCR page is mapped in L0 on any CPU at the point of
dealing with a TLB invalidation. It is incremented when a mapping
is made in the fixmap, and decremented when unmapped.

As it turns out, this tracking has several flaws:

- we are trying to invalidate TLBs, and the mapping is only an
opportunistic consequence of the TLB. Checking this counter to
decide whether a TLB needs to be invalidated may result in missed
invalidations.

- an L1 vcpu invalidating its own TLB (a very likely case) will not
succeed in invalidating the VNCR pseudo TLB because that page is
not mapped in L0 at this stage.

Given that this tracking fails at delivering the minimum guarantees
that are required and is only a performance optimisation, remove it
completely.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via stale memory mapping in KVM ARM64
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s KVM arm64 implementation contains an obsolete global VNCR mapping counter that determines whether a virtual-to-physical mapping is present in L0 during TLB invalidation. The counter logic can mistakenly report absence of a mapping, leading to missing or incorrect TLB invalidation. Based on the description, it is inferred that such incorrect handling could result in stale mapping entries that expose data across virtual machine contexts, potentially enabling information disclosure or privilege escalation. The weakness appears to be an improper memory consistency handling flaw.

Affected Systems

All Linux kernel releases that include the legacy VNCR mapping counter before its removal commit are affected. This applies to KVM running on ARM64 architectures, regardless of distribution. The patch is present in all kernel releases after the commit referenced in the advisory. Users of older kernels must upgrade to a release that contains the fix.

Risk and Exploitability

The vulnerability receives a CVSS score of 9.3, indicating critical severity. Its EPSS score is less than 1 %, suggesting that active exploitation is unlikely but still possible in targeted environments. The issue is not listed in the CISA KEV catalog. Attackers would need to run a malicious guest or possess kernel‑level access to trigger the incorrect TLB handling, making the attack vector local to the host hypervisor. Based on the description, it is inferred that the attacker must exploit the L1 guest’s TLB operations or achieve kernel-level escalated privileges on the host. Given the high severity, any vulnerable environment should be considered at risk until the patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 08:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the KVM arm64 VNCR mapping counter removal fix.
  • Reboot the host to activate the updated kernel.
  • If custom KVM modules are used, rebuild them against the new kernel headers to ensure consistency.

Generated by OpenCVE AI on September 18, 2026 at 08:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Remove VM-wide VNCR mapping counter The global VNCR mapping counter is used to decide whether an L1 provided VNCR page is mapped in L0 on any CPU at the point of dealing with a TLB invalidation. It is incremented when a mapping is made in the fixmap, and decremented when unmapped. As it turns out, this tracking has several flaws: - we are trying to invalidate TLBs, and the mapping is only an opportunistic consequence of the TLB. Checking this counter to decide whether a TLB needs to be invalidated may result in missed invalidations. - an L1 vcpu invalidating its own TLB (a very likely case) will not succeed in invalidating the VNCR pseudo TLB because that page is not mapped in L0 at this stage. Given that this tracking fails at delivering the minimum guarantees that are required and is only a performance optimisation, remove it completely.
Title KVM: arm64: Remove VM-wide VNCR mapping counter
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:07.892Z

Reserved: 2026-09-11T19:38:34.775Z

Link: CVE-2026-89915

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:00.553

Modified: 2026-09-16T15:18:17.760

Link: CVE-2026-89915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:00:08Z

Weaknesses