« Volver al listado

CVE-2026-89981

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

arm64: Don't read GMID_EL1 when MTE is disabled

__cpuinfo_store_cpu() gates the GMID_EL1 read on the raw ID_AA64PFR1_EL1, so it reads the register even when the kernel has disabled MTE (CONFIG_ARM64_MTE=n or arm64.nomte). KVM sets HCR_EL2.TID5 in that case, and pKVM injects an UNDEF the host cannot handle:

Only pKVM reaches it, and only after a CPU is offlined and brought back online: its CPU_ON relay sets the host HCR before the CPU enters EL1, while plain nVHE sets it at CPUHP_AP_KVM_ONLINE.

Gate the read on the CPU's own ID_AA64PFR1_EL1 with the command-line override applied, and on CONFIG_ARM64_MTE, which no register reflects.

Leer descripción completaMostrar menos

The boot CPU stores its registers before init_cpu_features() strips an unsafe override, so clamp against the hardware value here too.

Detalles técnicos trazas, registros y código del informe original
  Internal error: Oops - Undefined instruction: 0000000002000000 [#1]  SMP
  pc : __cpuinfo_store_cpu+0xf4/0x264
  Kernel panic - not syncing: Attempted to kill the idle task!

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89981",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f35abcbb8a084db4c24b66ccc8db0405c08e2f61",
              "lessThan": "d2d22ff377cd43f2e9660426ff22e3cd4c534637",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f35abcbb8a084db4c24b66ccc8db0405c08e2f61",
              "lessThan": "5445d64199626974269fcdf347769ad44b0bb53b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/arm64/include/asm/cpu.h",
            "arch/arm64/include/asm/cpufeature.h",
            "arch/arm64/kernel/cpufeature.c",
            "arch/arm64/kernel/cpuinfo.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/arm64/include/asm/cpu.h",
            "arch/arm64/include/asm/cpufeature.h",
            "arch/arm64/kernel/cpufeature.c",
            "arch/arm64/kernel/cpuinfo.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:09.037",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5445d64199626974269fcdf347769ad44b0bb53b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d2d22ff377cd43f2e9660426ff22e3cd4c534637",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: Don't read GMID_EL1 when MTE is disabled\n\n__cpuinfo_store_cpu() gates the GMID_EL1 read on the raw\nID_AA64PFR1_EL1, so it reads the register even when the kernel has\ndisabled MTE (CONFIG_ARM64_MTE=n or arm64.nomte). KVM sets HCR_EL2.TID5\nin that case, and pKVM injects an UNDEF the host cannot handle:\n\n  Internal error: Oops - Undefined instruction: 0000000002000000 [#1]  SMP\n  pc : __cpuinfo_store_cpu+0xf4/0x264\n  Kernel panic - not syncing: Attempted to kill the idle task!\n\nOnly pKVM reaches it, and only after a CPU is offlined and brought back\nonline: its CPU_ON relay sets the host HCR before the CPU enters EL1,\nwhile plain nVHE sets it at CPUHP_AP_KVM_ONLINE.\n\nGate the read on the CPU's own ID_AA64PFR1_EL1 with the command-line\noverride applied, and on CONFIG_ARM64_MTE, which no register reflects.\nThe boot CPU stores its registers before init_cpu_features() strips an\nunsafe override, so clamp against the hardware value here too."
    }
  ],
  "lastModified": "2026-09-16T11:17:09.037",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}