CVE-2026-90212
In the Linux kernel, the following vulnerability has been resolved:
arm64/efi: Avoid voluntary preemption with efi_mm installed
Gus reports a bad kernel memory access when using software PAN (CONFIG_ARM64_SW_TTBR0_PAN=y) on a machine with support for EFI runtime services:
This is because the fpsimd context management code called from __efi_fpsimd_begin() can preempt voluntarily, returning later to the EFI code with an incorrect value for TTBR0_EL1 thanks to the deferred mm switching used by the software PAN implementation.
Since EFI runtime services cannot preempt voluntarily and because the fpsimd switching code does not rely on the TTBR0_EL1 mappings, simply reorder the fpsimd switch so that it occurs before we change the page-table.
Detalles técnicos trazas, registros y código del informe original
Unable to handle kernel access to user memory outside uaccess routines
at virtual address 00000000f322ff30
Mem abort info:
ESR = 0x0000000096000004
FSC = 0x04: level 0 translation fault
Internal error: Oops: 0000000096000004 [#1] SMP
Workqueue: efi_rts_wq efi_call_rts
pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : efi_call_rts+0xd8/0x288
Call trace:
efi_call_rts+0xd8/0x288 (P)
process_one_work+0x178/0x4f8
worker_thread+0x194/0x328CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90212",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "a5baf582f4c026c25a206ac121bceade926aec74",
"lessThan": "829539c4a650544cb8e5e8690f2c2d0aa2c0e298",
"versionType": "git"
},
{
"status": "affected",
"version": "a5baf582f4c026c25a206ac121bceade926aec74",
"lessThan": "e98a9d0146372b046d863164025a66ab4488b972",
"versionType": "git"
}
],
"programFiles": [
"arch/arm64/kernel/efi.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/arm64/kernel/efi.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:16.430",
"references": [
{
"url": "https://git.kernel.org/stable/c/829539c4a650544cb8e5e8690f2c2d0aa2c0e298",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e98a9d0146372b046d863164025a66ab4488b972",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64/efi: Avoid voluntary preemption with efi_mm installed\n\nGus reports a bad kernel memory access when using software PAN\n(CONFIG_ARM64_SW_TTBR0_PAN=y) on a machine with support for EFI runtime\nservices:\n\n Unable to handle kernel access to user memory outside uaccess routines\n at virtual address 00000000f322ff30\n Mem abort info:\n ESR = 0x0000000096000004\n FSC = 0x04: level 0 translation fault\n Internal error: Oops: 0000000096000004 [#1] SMP\n Workqueue: efi_rts_wq efi_call_rts\n pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : efi_call_rts+0xd8/0x288\n Call trace:\n efi_call_rts+0xd8/0x288 (P)\n process_one_work+0x178/0x4f8\n worker_thread+0x194/0x328\n\nThis is because the fpsimd context management code called from\n__efi_fpsimd_begin() can preempt voluntarily, returning later to the EFI\ncode with an incorrect value for TTBR0_EL1 thanks to the deferred mm\nswitching used by the software PAN implementation.\n\nSince EFI runtime services cannot preempt voluntarily and because the\nfpsimd switching code does not rely on the TTBR0_EL1 mappings, simply\nreorder the fpsimd switch so that it occurs before we change the\npage-table."
}
],
"lastModified": "2026-09-17T17:17:16.430",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}