Description
In the Linux kernel, the following vulnerability has been resolved:

arm64: process: Fix context switching MTE store-only tag check

SCTLR_EL1.TCSO0 is set when user opt-in for MTE store-only tag check
mode. However, it is not part of SCTLR_USER_MASK which imply that on
context switch we never clear SCTLR_EL1.TCSO0, so we are leaking that
setting into another task.

Fix that by including SCTLR_EL1_TCSO0_MASK into SCTLR_USER_MASK
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure
Action: Patch
AI Analysis

Impact

The Linux kernel bug around the arm64 process context switch caused the SCTLR_EL1.TCSO0 flag, used for MTE store‑only tag checking, to be omitted from the user mask. As a result, when a context switch occurs the flag is never cleared, and the value leaks into the next task. This leakage can expose fine‑grained memory tag information or other privileged state to a task that should not see it, effectively allowing information disclosure between user space processes or between processes with different privilege levels. The flaw is a classic register or state leakage issue, commonly known as an information exposure weakness (CWE‑200).

Affected Systems

All Linux kernels running on arm64 architecture with MTE store‑only tag checking enabled are affected. The vendors listed are the Linux kernel maintainers. No specific kernel version or release is enumerated in the advisory, so any kernel before the inclusion of the patch in the mainline should be considered vulnerable.

Risk and Exploitability

Based on the description, it is inferred that the EPSS score is less than 1 %, indicating a very low likelihood that this vulnerability has been exploited in the wild. The vulnerability is not listed in the CISA KEV catalogue. The CVSS score is not provided, but the local nature of the flaw combined with the potential for data leakage implies a moderate overall risk. Exploitation requires that an attacker can run or influence both the victim process and the malicious process on the same system. The advisory recommends applying the patch immediately to prevent any potential leakage.

Generated by OpenCVE AI on September 20, 2026 at 03:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the MTE context‑switch patch (commits 00a73ce, 2f10bc3, or b8f070).
  • Reboot the system so that the updated kernel takes effect and registers are reinitialized.
  • If an update is not yet available, disable the MTE store‑only tag checking feature in the kernel configuration or kernel command line to avoid the leaking flag.

Generated by OpenCVE AI on September 20, 2026 at 03:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: arm64: process: Fix context switching MTE store-only tag check SCTLR_EL1.TCSO0 is set when user opt-in for MTE store-only tag check mode. However, it is not part of SCTLR_USER_MASK which imply that on context switch we never clear SCTLR_EL1.TCSO0, so we are leaking that setting into another task. Fix that by including SCTLR_EL1_TCSO0_MASK into SCTLR_USER_MASK
Title arm64: process: Fix context switching MTE store-only tag check
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:07.494Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90094

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:01.020

Modified: 2026-09-17T17:17:01.020

Link: CVE-2026-90094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:00:09Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor