Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Correctly handle end of VA space TLBI invalidation

Our TLB invalidation by VA code is based on comparing two ranges,
one defined by the TLB, and one defined by the TLBI instruction.

Each range is defined by a start and a size. However, the way the
comparison is done doesn't account for address rollover, as it
compares an address with (base + size). This works nicely until
this expression represent the last page/block in the TTBR1 VA space,
as the result is a big fat 0. And a failed TLB invalidation.

Rewrite the comparison in a way that is immune to the address
rollover (making the end address inclusive instead of exclusive),
and move this into a common helper that is used by both VA and IPA
invalidations, as suggested by Hyunwoo Kim (although the IPA version
didn't suffer from this particular problem, obviously).
Published: 2026-09-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption with potential privilege escalation
Action: Apply patch
AI Analysis

Impact

In KVM for ARM64, the TLB invalidation routine compared a virtual address range based on the TLB entry and the TLBI instruction. The comparison did not handle address rollover, treating the end of the range incorrectly as a zero address, which caused the invalidation to fail for the last page or block of the TTBR1 virtual address space. Consequently, stale TLB entries could remain, allowing virtual machines to access memory that should have been revalidated, potentially leading to memory corruption or escalation of privileges within the host.

Affected Systems

All Linux kernels that use the KVM driver on ARM 64 bit architectures are affected. No specific version information is provided, so any derivative of the Linux kernel that includes the buggy arm64 KVM TLB logic is vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that, at the time of this assessment, the likelihood of exploitation is very low, and the vulnerability is not listed in CISA’s KEV catalog. The problem is strictly in the kernel’s internal address comparison logic, so an exploit would most likely require the attacker to control or influence the virtual memory mapping of a VM or have other privileged access to the host. The attack surface is confined to ARM64 KVM usage, making it niche but severe for impacted environments.

Generated by OpenCVE AI on September 18, 2026 at 03:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a Linux kernel version that includes the patched KVM arm64 TLB invalidation logic.
  • Restart the host or KVM service to ensure the kernel’s new logic takes effect and all stale TLB entries are cleared.
  • If an immediate kernel upgrade is not possible, temporarily disable KVM for ARM64 virtual machines until a patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 03:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly handle end of VA space TLBI invalidation Our TLB invalidation by VA code is based on comparing two ranges, one defined by the TLB, and one defined by the TLBI instruction. Each range is defined by a start and a size. However, the way the comparison is done doesn't account for address rollover, as it compares an address with (base + size). This works nicely until this expression represent the last page/block in the TTBR1 VA space, as the result is a big fat 0. And a failed TLB invalidation. Rewrite the comparison in a way that is immune to the address rollover (making the end address inclusive instead of exclusive), and move this into a common helper that is used by both VA and IPA invalidations, as suggested by Hyunwoo Kim (although the IPA version didn't suffer from this particular problem, obviously).
Title KVM: arm64: Correctly handle end of VA space TLBI invalidation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:10.975Z

Reserved: 2026-09-11T19:38:34.775Z

Link: CVE-2026-89918

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:00.867

Modified: 2026-09-16T15:18:18.010

Link: CVE-2026-89918

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:45:01Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound