« Volver al listado

CVE-2026-90212

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

arm64/efi: Avoid voluntary preemption with efi_mm installed

Gus reports a bad kernel memory access when using software PAN (CONFIG_ARM64_SW_TTBR0_PAN=y) on a machine with support for EFI runtime services:

This is because the fpsimd context management code called from __efi_fpsimd_begin() can preempt voluntarily, returning later to the EFI code with an incorrect value for TTBR0_EL1 thanks to the deferred mm switching used by the software PAN implementation.

Since EFI runtime services cannot preempt voluntarily and because the fpsimd switching code does not rely on the TTBR0_EL1 mappings, simply reorder the fpsimd switch so that it occurs before we change the page-table.

Detalles técnicos trazas, registros y código del informe original
  Unable to handle kernel access to user memory outside uaccess routines
    at virtual address 00000000f322ff30
  Mem abort info:
    ESR = 0x0000000096000004
    FSC = 0x04: level 0 translation fault
  Internal error: Oops: 0000000096000004 [#1]  SMP
  Workqueue: efi_rts_wq efi_call_rts
  pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
  pc : efi_call_rts+0xd8/0x288
  Call trace:
   efi_call_rts+0xd8/0x288 (P)
   process_one_work+0x178/0x4f8
   worker_thread+0x194/0x328

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90212",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "a5baf582f4c026c25a206ac121bceade926aec74",
              "lessThan": "829539c4a650544cb8e5e8690f2c2d0aa2c0e298",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5baf582f4c026c25a206ac121bceade926aec74",
              "lessThan": "e98a9d0146372b046d863164025a66ab4488b972",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/arm64/kernel/efi.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/arm64/kernel/efi.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:16.430",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/829539c4a650544cb8e5e8690f2c2d0aa2c0e298",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e98a9d0146372b046d863164025a66ab4488b972",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64/efi: Avoid voluntary preemption with efi_mm installed\n\nGus reports a bad kernel memory access when using software PAN\n(CONFIG_ARM64_SW_TTBR0_PAN=y) on a machine with support for EFI runtime\nservices:\n\n  Unable to handle kernel access to user memory outside uaccess routines\n    at virtual address 00000000f322ff30\n  Mem abort info:\n    ESR = 0x0000000096000004\n    FSC = 0x04: level 0 translation fault\n  Internal error: Oops: 0000000096000004 [#1]  SMP\n  Workqueue: efi_rts_wq efi_call_rts\n  pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n  pc : efi_call_rts+0xd8/0x288\n  Call trace:\n   efi_call_rts+0xd8/0x288 (P)\n   process_one_work+0x178/0x4f8\n   worker_thread+0x194/0x328\n\nThis is because the fpsimd context management code called from\n__efi_fpsimd_begin() can preempt voluntarily, returning later to the EFI\ncode with an incorrect value for TTBR0_EL1 thanks to the deferred mm\nswitching used by the software PAN implementation.\n\nSince EFI runtime services cannot preempt voluntarily and because the\nfpsimd switching code does not rely on the TTBR0_EL1 mappings, simply\nreorder the fpsimd switch so that it occurs before we change the\npage-table."
    }
  ],
  "lastModified": "2026-09-17T17:17:16.430",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}