{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90383","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.809Z","datePublished":"2026-09-17T16:09:19.875Z","dateUpdated":"2026-09-18T17:54:59.978Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:54:59.978Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: sgi-gru: remove interrupt-context page-table walks\n\nThe GRU TLB miss handler walks a process's page tables without holding\npage-table locks or a reference to the mapped page. It also uses a kernel\npage-table accessor on user page tables and supports only PMD-level large\nmappings on x86-64.\n\nRemove the direct walker. Send interrupt faults directly to user polling\nmode so the existing call-OS fallback retries them in process context.\n\nRemove the mmap-lock failure statistic that can no longer be incremented."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker supplies the faulting VA by writing a virtual-mode GRU vload/vstore/bcopy into the mmap'd GSEG on /dev/gru. gru_fault loads the context; the miss is handled by gru_intr (default GRU_OPT_MISS_FMM_INTR) or ioctl GRU_USER_CALL_OS (gru_handle_user_call_os), both of which called atomic_pte_lookup on that missvaddr.\nAC:L - gru_create_new_context defaults to GRU_OPT_MISS_FMM_INTR, so a mapped-mode GRU instruction reliably hits gru_intr, which mmap_read_trylocks gts->ts_mm and runs atomic_pte_lookup. A 1GB hugetlb VMA is mis-walked with no race because pud_leaf is never checked; a second thread of the same process can also madvise/unmap during the unlocked walk.\nPR:L - gru_fops has no .open method and gru_file_mmap/gru_file_unlocked_ioctl do not call capable(). An unprivileged process that can open miscdevice \"gru\" (/dev/gru) can mmap the GSEG, ioctl GRU_CREATE_CONTEXT, and issue GRU instructions that reach atomic_pte_lookup; only gru_unload_all_contexts requires CAP_SYS_ADMIN.\nUI:N - The attacker alone opens /dev/gru, maps the GSEG, calls GRU_CREATE_CONTEXT, and issues the GRU instruction or GRU_USER_CALL_OS ioctl; no other user needs to act.\nS:U - atomic_pte_lookup feeds a GPA to tfh_write_restart on the host GRU chiplet. A bad PFN lets GRU DMA into host kernel or other-process memory, which is privilege escalation in the same kernel authority, not a guest-to-host or IOMMU-domain crossing.\nC:H - atomic_pte_lookup never tests pud_leaf, so pud_pgtable() on a 1GB hugetlb leaf treats attacker-controlled hugepage bytes as PMD/PTE entries. pte_pfn of that crafted entry is installed by tfh_write_restart, and gru_vload/bcopy then reads that physical page into the attacker-mapped GSEG. The walk also never pins the page, so a stale PFN can be read after reuse.\nI:H - gru_vstore, gru_bcopy, and AMO opcodes write through the GRU TLB entry programmed by tfh_write_restart. A PFN taken from the pud_leaf miswalk of attacker-controlled 1GB hugepage contents, or from an unpinned PTE reused after free, is therefore an arbitrary physical write.\nA:H - pte_offset_kernel() on a pud_leaf 1GB mapping (or on a PMD that is not a table) computes __va of a non-page-table PFN and dereferences it in gru_intr/atomic_pte_lookup, oopsing the kernel. GRU DMA through a stale unpinned PFN can also panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/misc/sgi-gru/grufault.c","drivers/misc/sgi-gru/gruprocfs.c","drivers/misc/sgi-gru/grutables.h"],"versions":[{"version":"142586409c8be7dc071bb94d7cd2d69ccfd99b6b","lessThan":"877423f595b60f8fe7c18b64a5d283d9e1732a13","status":"affected","versionType":"git"},{"version":"142586409c8be7dc071bb94d7cd2d69ccfd99b6b","lessThan":"6248eb1833ff0adfdbbadd5f846c2f22e02a01b0","status":"affected","versionType":"git"},{"version":"142586409c8be7dc071bb94d7cd2d69ccfd99b6b","lessThan":"ef81e4a1628ecfb9cfc442de10883f383faf17a1","status":"affected","versionType":"git"},{"version":"142586409c8be7dc071bb94d7cd2d69ccfd99b6b","lessThan":"928a8e9f523df845fc496bcb9811013b67aabec5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/misc/sgi-gru/grufault.c","drivers/misc/sgi-gru/gruprocfs.c","drivers/misc/sgi-gru/grutables.h"],"versions":[{"version":"2.6.27","status":"affected"},{"version":"0","lessThan":"2.6.27","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.27","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.27","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.27","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.27","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/877423f595b60f8fe7c18b64a5d283d9e1732a13"},{"url":"https://git.kernel.org/stable/c/6248eb1833ff0adfdbbadd5f846c2f22e02a01b0"},{"url":"https://git.kernel.org/stable/c/ef81e4a1628ecfb9cfc442de10883f383faf17a1"},{"url":"https://git.kernel.org/stable/c/928a8e9f523df845fc496bcb9811013b67aabec5"}],"title":"misc: sgi-gru: remove interrupt-context page-table walks","x_generator":{"engine":"bippy-1.2.0"}}}}