Description
In the Linux kernel, the following vulnerability has been resolved:

arm64/efi: Avoid voluntary preemption with efi_mm installed

Gus reports a bad kernel memory access when using software PAN
(CONFIG_ARM64_SW_TTBR0_PAN=y) on a machine with support for EFI runtime
services:

Unable to handle kernel access to user memory outside uaccess routines
at virtual address 00000000f322ff30
Mem abort info:
ESR = 0x0000000096000004
FSC = 0x04: level 0 translation fault
Internal error: Oops: 0000000096000004 [#1] SMP
Workqueue: efi_rts_wq efi_call_rts
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : efi_call_rts+0xd8/0x288
Call trace:
efi_call_rts+0xd8/0x288 (P)
process_one_work+0x178/0x4f8
worker_thread+0x194/0x328

This is because the fpsimd context management code called from
__efi_fpsimd_begin() can preempt voluntarily, returning later to the EFI
code with an incorrect value for TTBR0_EL1 thanks to the deferred mm
switching used by the software PAN implementation.

Since EFI runtime services cannot preempt voluntarily and because the
fpsimd switching code does not rely on the TTBR0_EL1 mappings, simply
reorder the fpsimd switch so that it occurs before we change the
page-table.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption potentially enabling privilege escalation
Action: Apply patch ASAP
AI Analysis

Impact

The vulnerability occurs when the Linux arm64 kernel handles EFI runtime services with software PAN enabled. During a voluntary preemption, the fpsimd context switch is performed after the TTBR0_EL1 page‑table change, leaving the kernel with an incorrect translation table pointer. This allows the kernel to dereference user memory addresses incorrectly, causing a kernel oops and potential loss of confidentiality, integrity or availability, and opening a path for privilege escalation.

Affected Systems

Affected systems are Linux kernel builds for arm64 that enable EFI runtime services and have the CONFIG_ARM64_SW_TTBR0_PAN setting enabled. No specific version numbers are listed, but the issue applies to any arm64 kernel containing the described fpsimd/context‑switch code path.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not in CISA KEV, indicating a low likelihood of widespread exploitation at present. However, the effect is severe: a kernel crash or escalation can be achieved by a user process, making the impact potentially critical. The likely attack vector is through normal user‑land execution on an impacted kernel, exploiting the improper preemption behavior during EFI calls.

Generated by OpenCVE AI on September 19, 2026 at 03:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that implements the fpsimd reordering fix
  • If an update is unavailable, disable CONFIG_ARM64_SW_TTBR0_PAN in the kernel configuration or remove it from the build
  • If disabling PAN is not an option, avoid running EFI runtime services or reboot the system into a safe mode
  • Monitor kernel logs for “Unable to handle kernel access to user memory” messages as an early indicator of an exploit attempt

Generated by OpenCVE AI on September 19, 2026 at 03:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: arm64/efi: Avoid voluntary preemption with efi_mm installed Gus reports a bad kernel memory access when using software PAN (CONFIG_ARM64_SW_TTBR0_PAN=y) on a machine with support for EFI runtime services: Unable to handle kernel access to user memory outside uaccess routines at virtual address 00000000f322ff30 Mem abort info: ESR = 0x0000000096000004 FSC = 0x04: level 0 translation fault Internal error: Oops: 0000000096000004 [#1] SMP Workqueue: efi_rts_wq efi_call_rts pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : efi_call_rts+0xd8/0x288 Call trace: efi_call_rts+0xd8/0x288 (P) process_one_work+0x178/0x4f8 worker_thread+0x194/0x328 This is because the fpsimd context management code called from __efi_fpsimd_begin() can preempt voluntarily, returning later to the EFI code with an incorrect value for TTBR0_EL1 thanks to the deferred mm switching used by the software PAN implementation. Since EFI runtime services cannot preempt voluntarily and because the fpsimd switching code does not rely on the TTBR0_EL1 mappings, simply reorder the fpsimd switch so that it occurs before we change the page-table.
Title arm64/efi: Avoid voluntary preemption with efi_mm installed
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:26.104Z

Reserved: 2026-09-11T19:38:34.793Z

Link: CVE-2026-90212

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:16.430

Modified: 2026-09-17T17:17:16.430

Link: CVE-2026-90212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:15:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-665

    Improper Initialization