Description
In the Linux kernel, the following vulnerability has been resolved:

misc: sgi-gru: remove interrupt-context page-table walks

The GRU TLB miss handler walks a process's page tables without holding
page-table locks or a reference to the mapped page. It also uses a kernel
page-table accessor on user page tables and supports only PMD-level large
mappings on x86-64.

Remove the direct walker. Send interrupt faults directly to user polling
mode so the existing call-OS fallback retries them in process context.

Remove the mmap-lock failure statistic that can no longer be incremented.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Kernel
AI Analysis

Impact

The Linux kernel GRU TLB miss handler performs page table walks during interrupt context without acquiring page-table locks or retaining a reference to the accessed page. It also uses a kernel-mode page-table accessor on user page tables. This defect allows a locally privileged attacker to induce a TLB miss that triggers the unsafe walk, potentially reading or corrupting page table entries. The result can be arbitrary memory corruption or privilege escalation. The root issue is an improper synchronization of shared kernel data (CWE 362).

Affected Systems

All Linux kernel releases that ship the GRU driver and its TLB miss handler before the commits referenced in the advisory are affected. This includes every version of the kernel that has not yet incorporated the fix that removes the direct walker and replaces it with a polling mode handler. Even are at risk if they contain the vulnerable code.

Risk and Exploitability

The CVSS score of 7.8 marks this flaw as high severity, and the EPSS score of less than 1% indicates that automated exploitation is uncommon. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread attacks. Exploitation requires triggering a TLB miss in an interrupt context, so the attack vector is kernel-level and would normally demand local or elevated privileges. Based on the description, the attack is likely of medium complexity but could lead to severe compromise if achieved.

Generated by OpenCVE AI on September 19, 2026 at 15:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the GRU TLB miss handler fix submitted in commit 6248eb1833ff0adfdbbadd5f846c2f22e02a01b0.
  • If an immediate upgrade is not possible, disable GRU support by removing the GRU kernel module or disabling GRU CONFIG options in the kernel configuration, so the vulnerable code path is never exercised.
  • If the kernel has been compiled with the failing code path, manually apply the patch from the commit referenced in the advisory before rebooting the system.

Generated by OpenCVE AI on September 19, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: misc: sgi-gru: remove interrupt-context page-table walks The GRU TLB miss handler walks a process's page tables without holding page-table locks or a reference to the mapped page. It also uses a kernel page-table accessor on user page tables and supports only PMD-level large mappings on x86-64. Remove the direct walker. Send interrupt faults directly to user polling mode so the existing call-OS fallback retries them in process context. Remove the mmap-lock failure statistic that can no longer be incremented.
Title misc: sgi-gru: remove interrupt-context page-table walks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:59.978Z

Reserved: 2026-09-11T19:38:34.809Z

Link: CVE-2026-90383

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:37.660

Modified: 2026-09-18T18:17:56.450

Link: CVE-2026-90383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:30:06Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')