{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98283","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.335Z","datePublished":"2026-10-06T08:45:44.593Z","dateUpdated":"2026-10-07T06:49:54.642Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:54.642Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()\n\nkvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops\nmmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a\nreference on the kvm_nested_guest pointer obtained from the IDR.  A\nconcurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race\nthrough kvmhv_flush_nested() -> kvmhv_remove_nested() -> idr_remove /\n--refcnt -> kvmhv_release_nested() -> kfree(gp) in that window, leaving\nthe iterating vCPU with a dangling pointer.  The subsequent\nmutex_lock(&gp->tlb_lock) and accesses to gp->shadow_pgtable,\ngp->shadow_lpid and gp->l1_host all touch freed memory.  The free path\nis fully L1-controlled.\n\nFix this by incrementing gp->refcnt inside the loop before dropping\nmmu_lock, mirroring what kvmhv_get_nested() does, and releasing the\nreference with kvmhv_put_nested() after the per-guest work completes.\nThis is the same get/put discipline already used at every other\ncall site that drops mmu_lock while holding a nested-guest pointer."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The trigger is the H_TLB_INVALIDATE hcall made by code running inside an L1 guest on the POWER KVM-HV host, via kvmppc_pseries_do_hcall -> kvmhv_do_nested_tlbie -> kvmhv_emulate_priv_tlbie -> kvmhv_emulate_tlbie_all_lpid. No network protocol carries the input; the attacker needs code execution in a local guest.\nAC:L - The L1 controls both sides of the race: one vCPU issues tlbie is=3 (all-LPID walk), another issues is=2 ric=2 after zeroing its own partition-table entry so kvmhv_flush_nested() calls kvmhv_remove_nested() and kfree(gp). Contention on gp->tlb_lock widens the window and the attempt can be repeated. The only outside requirement is the VMM enabling KVM_CAP_PPC_NESTED_HV.\nPR:L - The attacker needs kernel/hypervisor-mode code in a nested-enabled L1 guest, which an ordinary tenant owns, but holds no privilege on the L0 host. The nesting_enabled() check is the only gate before kvmhv_do_nested_tlbie().\nUI:N - The L1 guest issues every hcall and controls every partition-table entry involved. No host operator or other user has to do anything.\nS:C - A guest-controlled vulnerability corrupts memory in the L0 host kernel (the kfree'd kvm_nested_guest object), which crosses the guest-to-host boundary.\nC:H - After the free, kvmhv_emulate_tlbie_lpid() reads gp->shadow_pgtable, gp->shadow_lpid and gp->l1_host from the dangling object. A reclaimed object lets the guest steer host page-table walks and host data reads.\nI:H - The freed gp is used for mutex_lock(&gp->tlb_lock), kvmppc_free_pgtable_radix() on gp->shadow_pgtable, and kvmhv_flush_nested()/kvmhv_put_nested() refcount writes. With a reclaimed object, these become host-kernel write and free primitives the guest controls.\nA:H - Using the freed kvm_nested_guest in the host can oops or panic the L0 host kernel, taking down every guest on the machine. The L1 can trigger it again at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/powerpc/kvm/book3s_hv_nested.c"],"versions":[{"version":"e3b6b4661527e821ffbe3db83952fdb1e6e47c49","lessThan":"4d8f7b1f586375df8bce23a0909566ad5e852259","status":"affected","versionType":"git"},{"version":"e3b6b4661527e821ffbe3db83952fdb1e6e47c49","lessThan":"e37fba1ba69385cff2d0e60b371ee19e7d1852d1","status":"affected","versionType":"git"},{"version":"e3b6b4661527e821ffbe3db83952fdb1e6e47c49","lessThan":"24b634852413229bb8340d908b115c3365f3a247","status":"affected","versionType":"git"},{"version":"e3b6b4661527e821ffbe3db83952fdb1e6e47c49","lessThan":"fbf69b7d0555ee83c871f58750770f74b7179ad1","status":"affected","versionType":"git"},{"version":"e3b6b4661527e821ffbe3db83952fdb1e6e47c49","lessThan":"ec2d7a52b3996ae81131617b4afc0af31583c1b4","status":"affected","versionType":"git"},{"version":"e3b6b4661527e821ffbe3db83952fdb1e6e47c49","lessThan":"51938dfa8a51a4f85328413fca9b6e21f9d2d088","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/powerpc/kvm/book3s_hv_nested.c"],"versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/4d8f7b1f586375df8bce23a0909566ad5e852259"},{"url":"https://git.kernel.org/stable/c/e37fba1ba69385cff2d0e60b371ee19e7d1852d1"},{"url":"https://git.kernel.org/stable/c/24b634852413229bb8340d908b115c3365f3a247"},{"url":"https://git.kernel.org/stable/c/fbf69b7d0555ee83c871f58750770f74b7179ad1"},{"url":"https://git.kernel.org/stable/c/ec2d7a52b3996ae81131617b4afc0af31583c1b4"},{"url":"https://git.kernel.org/stable/c/51938dfa8a51a4f85328413fca9b6e21f9d2d088"}],"title":"KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()","x_generator":{"engine":"bippy-1.2.0"}}}}