Description
In the Linux kernel, the following vulnerability has been resolved:

arm64: Don't read GMID_EL1 when MTE is disabled

__cpuinfo_store_cpu() gates the GMID_EL1 read on the raw
ID_AA64PFR1_EL1, so it reads the register even when the kernel has
disabled MTE (CONFIG_ARM64_MTE=n or arm64.nomte). KVM sets HCR_EL2.TID5
in that case, and pKVM injects an UNDEF the host cannot handle:

Internal error: Oops - Undefined instruction: 0000000002000000 [#1] SMP
pc : __cpuinfo_store_cpu+0xf4/0x264
Kernel panic - not syncing: Attempted to kill the idle task!

Only pKVM reaches it, and only after a CPU is offlined and brought back
online: its CPU_ON relay sets the host HCR before the CPU enters EL1,
while plain nVHE sets it at CPUHP_AP_KVM_ONLINE.

Gate the read on the CPU's own ID_AA64PFR1_EL1 with the command-line
override applied, and on CONFIG_ARM64_MTE, which no register reflects.
The boot CPU stores its registers before init_cpu_features() strips an
unsafe override, so clamp against the hardware value here too.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Kernel
AI Analysis

Impact

The Linux kernel on ARM64 may read the GMID_EL1 register even when the Machine Type Extension (MTE) is disabled. Because that register is not present in that configuration, the CPU raises an undefined instruction exception that the kernel cannot recover from, causing a kernel panic and denying service. The flaw is caused by missing gating of the read based on the CPU’s ID_AA64PFR1_EL1 value and the CONFIG_ARM64_MTE flag. The likely attack vector is a KVM virtual machine or an attacker that can trigger CPU hot‑plug or configuration changes, as the issue is triggered when a CPU is offlined and brought back online or when KVM sets HCR_EL2.TID5.

Affected Systems

All Linux ARM64 kernels that are compiled with CONFIG_ARM64_MTE set to n or use the arm64.nomte command line option are potentially affected. The advisory does not list specific kernel versions, so any ARM64 kernel built without MTE support is vulnerable. Systems that employ KVM for virtualization are the most likely to encounter the failure upon CPU state transitions.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not in the CISA KEV catalog, indicating a low probability of exploitation. However, the impact is severe: a single trigger will crash the host kernel and service. Exploitability requires a kernel with MTE disabled and the ability to force CPU re‑online events or influence KVM configuration, which typically limits the threat to privileged or local attackers.

Generated by OpenCVE AI on September 18, 2026 at 07:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the GMID_EL1 read fix.
  • If an update is not possible, rebuild the kernel with MTE support enabled (CONFIG_ARM64_MTE=y) so the register is never accessed when MTE is disabled.
  • If neither of the above is feasible, consider disabling or reconfiguring KVM usage when MTE is disabled to avoid setting HCR_EL2.TID5 during CPU state transitions.
  • After applying a change, monitor kernel logs for "Undefined instruction" or oops messages to confirm system stability.

Generated by OpenCVE AI on September 18, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: arm64: Don't read GMID_EL1 when MTE is disabled __cpuinfo_store_cpu() gates the GMID_EL1 read on the raw ID_AA64PFR1_EL1, so it reads the register even when the kernel has disabled MTE (CONFIG_ARM64_MTE=n or arm64.nomte). KVM sets HCR_EL2.TID5 in that case, and pKVM injects an UNDEF the host cannot handle: Internal error: Oops - Undefined instruction: 0000000002000000 [#1] SMP pc : __cpuinfo_store_cpu+0xf4/0x264 Kernel panic - not syncing: Attempted to kill the idle task! Only pKVM reaches it, and only after a CPU is offlined and brought back online: its CPU_ON relay sets the host HCR before the CPU enters EL1, while plain nVHE sets it at CPUHP_AP_KVM_ONLINE. Gate the read on the CPU's own ID_AA64PFR1_EL1 with the command-line override applied, and on CONFIG_ARM64_MTE, which no register reflects. The boot CPU stores its registers before init_cpu_features() strips an unsafe override, so clamp against the hardware value here too.
Title arm64: Don't read GMID_EL1 when MTE is disabled
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:58.056Z

Reserved: 2026-09-11T19:38:34.779Z

Link: CVE-2026-89981

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:09.037

Modified: 2026-09-16T11:17:09.037

Link: CVE-2026-89981

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation