CVE-2026-89914
9.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Sign-extend VA for range-based TLBI invalidation
When the decode_range_tlbi() helper was moved to be used for S1 TLBIs, the required sign extension was omitted. Add it.
As a result, special care must be taken to not overflow PA bits when this is used for S2 invalidation.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 85bba00425ae0b4b30938ebfdde6d986e5423aff < 72bce82c4171bf330919ff1b64dc0a36c254ec7d | affected |
| Linux | Linux | 85bba00425ae0b4b30938ebfdde6d986e5423aff < 3feb83918e30f0472e058224b926ebfe8a064fac | affected |
| Linux | Linux | 85bba00425ae0b4b30938ebfdde6d986e5423aff < 2393470085649f0b973ecceb26fe8fc71edde0c1 | affected |
| Linux | Linux | 6.16 | affected |
| Linux | Linux | 0 < 6.16 | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/72bce82c4171bf330919ff1b64dc0a36c254ec7d
- https://git.kernel.org/stable/c/3feb83918e30f0472e058224b926ebfe8a064fac
- https://git.kernel.org/stable/c/2393470085649f0b973ecceb26fe8fc71edde0c1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.