« Volver al listado

CVE-2026-64229

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

x86/mm: Disable broadcast TLB flush when PCID is disabled

Booting with "nopcid" clears X86_FEATURE_PCID and keeps CR4.PCIDE from being set to one. On AMD CPUs that support INVLPGB, broadcast TLB flushing remains enabled.

There are two checks that decide whether the global ASID code runs, mm_global_asid() and consider_global_asid(), that key off of the X86_FEATURE_INVLPGB feature. Once an mm becomes active on more than three CPUs, consider_global_asid() assigns it a global ASID, after which flush_tlb_mm_range() takes the broadcast_tlb_flush() path using a non-zero PCID. Issuing an INVLPGB with a non-zero PCID while CR4.PCIDE is not set results in a #GP:

Leer descripción completaMostrar menos

All processors that support broadcast TLB invalidation also have PCID support, so it is only the "nopcid" scenario that is of concern. In this situation just disable the broadcast TLB support using the CPUID dependency support by making X86_FEATURE_INVLPGB dependent on X86_FEATURE_PCID.

Detalles técnicos trazas, registros y código del informe original
  Oops: general protection fault, kernel NULL pointer dereference 0x1: 0000 [#1] SMP NOPTI
  CPU: 158 UID: 0 PID: 3119 Comm: snap Not tainted 7.1.0-rc3 #1 PREEMPT(full)
  Hardware name: ...
  RIP: 0010:broadcast_tlb_flush
  Code: ... 89 da 48 83 c8 07 <0f> 01 fe eb 08 cc cc cc ...
  Call Trace:
   <TASK>
   flush_tlb_mm_range
   ptep_clear_flush
   wp_page_copy
   ? _raw_spin_unlock
   __handle_mm_fault
   handle_mm_fault
   do_user_addr_fault
   exc_page_fault
   asm_exc_page_fault

  [ bp: Massage commit message. ]

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-64229",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4afeb0ed1753ebcad93ee3b45427ce85e9c8ec40",
              "lessThan": "fed725cace3ab1c4f7f8182e35029a603d953187",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4afeb0ed1753ebcad93ee3b45427ce85e9c8ec40",
              "lessThan": "d2d6d21286719b454d5d87a8758c23d2377d88a2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4afeb0ed1753ebcad93ee3b45427ce85e9c8ec40",
              "lessThan": "44126343d58c68adaa8343fbf1c07dd20078c35e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/x86/kernel/cpu/cpuid-deps.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.35",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/x86/kernel/cpu/cpuid-deps.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-24T16:16:52.023",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/44126343d58c68adaa8343fbf1c07dd20078c35e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d2d6d21286719b454d5d87a8758c23d2377d88a2",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fed725cace3ab1c4f7f8182e35029a603d953187",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm: Disable broadcast TLB flush when PCID is disabled\n\nBooting with \"nopcid\" clears X86_FEATURE_PCID and keeps CR4.PCIDE from being\nset to one. On AMD CPUs that support INVLPGB, broadcast TLB flushing remains\nenabled.\n\nThere are two checks that decide whether the global ASID code runs,\nmm_global_asid() and consider_global_asid(), that key off of the\nX86_FEATURE_INVLPGB feature. Once an mm becomes active on more than three\nCPUs, consider_global_asid() assigns it a global ASID, after which\nflush_tlb_mm_range() takes the broadcast_tlb_flush() path using a non-zero\nPCID. Issuing an INVLPGB with a non-zero PCID while CR4.PCIDE is not set\nresults in a #GP:\n\n  Oops: general protection fault, kernel NULL pointer dereference 0x1: 0000 [#1] SMP NOPTI\n  CPU: 158 UID: 0 PID: 3119 Comm: snap Not tainted 7.1.0-rc3 #1 PREEMPT(full)\n  Hardware name: ...\n  RIP: 0010:broadcast_tlb_flush\n  Code: ... 89 da 48 83 c8 07 <0f> 01 fe eb 08 cc cc cc ...\n  Call Trace:\n   <TASK>\n   flush_tlb_mm_range\n   ptep_clear_flush\n   wp_page_copy\n   ? _raw_spin_unlock\n   __handle_mm_fault\n   handle_mm_fault\n   do_user_addr_fault\n   exc_page_fault\n   asm_exc_page_fault\n\nAll processors that support broadcast TLB invalidation also have PCID support,\nso it is only the \"nopcid\" scenario that is of concern. In this situation just\ndisable the broadcast TLB support using the CPUID dependency support by making\nX86_FEATURE_INVLPGB dependent on X86_FEATURE_PCID.\n\n  [ bp: Massage commit message. ]"
    }
  ],
  "lastModified": "2026-08-13T12:00:00.910",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "264F6745-E680-4AA9-A01E-4F9E3E10F604",
              "versionEndExcluding": "6.18.35",
              "versionStartIncluding": "6.15"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0520D091-FC52-4A50-AF07-70AE7D08B750",
              "versionEndExcluding": "7.0.11",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}