{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98164","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.321Z","datePublished":"2026-09-29T12:02:12.574Z","dateUpdated":"2026-10-07T06:49:16.773Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:16.773Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/mmu: Check write tracking in all address spaces\n\nkvm_gfn_is_write_tracked() checks only the supplied memslot, but page\ntracking is per-address-space and shadow pages are shared across all\naddress spaces.  With SMM, a GFN can therefore be write-tracked in one\naddress space and appear untracked through the other.\n\nCheck the supplied slot first, then the slot for the other address space.\nThis ensures all callers honor write tracking regardless of the active\naddress space.  In particular, it prevents mmu_try_to_unsync_pages() from\nmarking an upper-level shadow page unsync and eventually triggering the\nBUG in pte_list_remove().\n\n[invert direction of the conditional. - Paolo]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The fix patches kvm_gfn_is_write_tracked(), called from mmu_try_to_unsync_pages() via make_spte() on a vCPU page fault. Reaching it needs a VM with an SMM address space (KVM_SET_USER_MEMORY_REGION with as_id 1) driven through KVM_RUN on /dev/kvm. No remote protocol carries the input.\nAC:L - The attacker builds every precondition: a gPT shadowed and tracked in the as_id 0 slot, then a write to that gfn while in SMM, which checks only the as_id 1 slot and unsyncs an upper-level SP. A later sync deterministically reaches pte_list_remove; no race or outside state is needed.\nPR:L - Needs only an fd on /dev/kvm (commonly 0666 or kvm group) to create the VM, its SMM memslots and its own SMM code. No init-namespace root or capability is checked on the KVM_CREATE_VM/KVM_SET_USER_MEMORY_REGION/KVM_RUN path.\nUI:N - The attacker's own process runs the VM and triggers the page fault and the later root sync (kvm_mmu_sync_roots/kvm_sync_page) on its own. No other user does anything.\nS:U - I score the local VMM-process attacker, who controls guest SMM code. A guest-only trigger would need firmware to write chosen bytes into a gPT while in SMM, which kernel code cannot demonstrate. So the impact stays within the host kernel's authority.\nC:H - Syncing an unsynced upper-level SP runs FNAME(sync_spte) on non-leaf SPTEs. shadowed_translation is uninitialised for those entries (no __GFP_ZERO), so a gfn match makes make_spte() build a huge leaf from spte_to_pfn() of the non-leaf SPTE. That maps KVM's child page-table page, and nearby host memory, readable into the guest.\nI:N - Non-leaf SPTEs from make_nonleaf_spte() lack shadow_host_writable_mask, so the bogus leaf built in sync_spte has ACC_WRITE stripped. I found no code path where this bug lets the guest write host memory.\nA:H - Otherwise sync_spte calls drop_spte() on the non-leaf SPTE with a mismatched gfn. rmap_remove() then hits KVM_BUG_ON_DATA_CORRUPTION in pte_list_remove(), a BUG_ON with mmu_lock held when CONFIG_BUG_ON_DATA_CORRUPTION=y (the BUG the fix cites), crashing the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/x86/kvm/mmu/page_track.c"],"versions":[{"version":"699023e239658e62da6f42f47d31b54788521ec1","lessThan":"09aa68552d2542cc6c23edd1568ac265dc5d886f","status":"affected","versionType":"git"},{"version":"699023e239658e62da6f42f47d31b54788521ec1","lessThan":"429b6f43b4d8c98988fdca99e02dc156134e3d77","status":"affected","versionType":"git"},{"version":"699023e239658e62da6f42f47d31b54788521ec1","lessThan":"d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212a","status":"affected","versionType":"git"},{"version":"699023e239658e62da6f42f47d31b54788521ec1","lessThan":"c0a9bd5fca0b5f2dea32b0fc31350e71e8648112","status":"affected","versionType":"git"},{"version":"699023e239658e62da6f42f47d31b54788521ec1","lessThan":"ec8fcaf354c1cbb36755d48e9f5a00c9591349e5","status":"affected","versionType":"git"},{"version":"699023e239658e62da6f42f47d31b54788521ec1","lessThan":"0f38453cdb2e17566ccb7c0f3dabd5bd21caca26","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/x86/kvm/mmu/page_track.c"],"versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","status":"unaffected","versionType":"semver"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.1.187"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.6.156"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.12.108"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.18.49"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"7.1.13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/09aa68552d2542cc6c23edd1568ac265dc5d886f"},{"url":"https://git.kernel.org/stable/c/429b6f43b4d8c98988fdca99e02dc156134e3d77"},{"url":"https://git.kernel.org/stable/c/d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212a"},{"url":"https://git.kernel.org/stable/c/c0a9bd5fca0b5f2dea32b0fc31350e71e8648112"},{"url":"https://git.kernel.org/stable/c/ec8fcaf354c1cbb36755d48e9f5a00c9591349e5"},{"url":"https://git.kernel.org/stable/c/0f38453cdb2e17566ccb7c0f3dabd5bd21caca26"}],"title":"KVM: x86/mmu: Check write tracking in all address spaces","x_generator":{"engine":"bippy-1.2.0"}}}}