CVE-2026-64229: x86/mm: Disable broadcast TLB flush when PCID is disabled
In the Linux kernel, the following vulnerability has been resolved:
x86/mm: Disable broadcast TLB flush when PCID is disabled
Booting with "nopcid" clears X86FEATUREPCID and keeps CR4.PCIDE from being set to one. On AMD CPUs that support INVLPGB, broadcast TLB flushing remains enabled.
There are two checks that decide whether the global ASID code runs, mmglobalasid() and considerglobalasid(), that key off of the X86FEATUREINVLPGB feature. Once an mm becomes active on more than three CPUs, considerglobalasid() assigns it a global ASID, after which flushtlbmmrange() takes the broadcasttlbflush() path using a non-zero PCID. Issuing an INVLPGB with a non-zero PCID while CR4.PCIDE is not set results in a #GP:
Oops: general protection fault, kernel NULL pointer dereference 0x1: 0000 [#1] SMP NOPTI CPU: 158 UID: 0 PID: 3119 Comm: snap Not tainted 7.1.0-rc3 #1 PREEMPT(full) Hardware name: ... RIP: 0010:broadcasttlbflush Code: ... 89 da 48 83 c8 07 <0f> 01 fe eb 08 cc cc cc ... Call Trace: <TASK> flushtlbmmrange ptepclearflush wppagecopy ? rawspinunlock handlemmfault handlemmfault douseraddrfault excpagefault asmexcpagefault
All processors that support broadcast TLB invalidation also have PCID support, so it is only the "nopcid" scenario that is of concern. In this situation just disable the broadcast TLB support using the CPUID dependency support by making X86FEATUREINVLPGB dependent on X86FEATUREPCID.
[ bp: Massage commit message. ]
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernel x86/mm broadcast TLB flushto a version that resolves this vulnerability.Patch x86/mm: Disable broadcast TLB flush when PCID is disabled - Configuration
Boot the system with the "nopcid" kernel parameter so that booting clears X86_FEATURE_PCID (while CR4.PCIDE remains unset) to avoid issuing an INVLPGB with a non-zero PCID when CR4.PCIDE is not set.
Linux kernel x86 (boot parameter) nopcid = enabled
Event History
Frequently Asked Questions
Which systems are exposed to this fault?
Systems running on AMD CPUs that support INVLPGB are affected when booted with the "nopcid" kernel parameter. The failure condition is reached after an address space becomes active on more than three CPUs and is assigned a global ASID.
What does an attacker or triggering workload need to do?
The issue is locally reachable and requires low privileges, with no user interaction. A workload must cause the affected memory-management path to issue a broadcast TLB flush with a non-zero PCID while PCID is disabled, resulting in a general protection fault and kernel crash.
Are default kernel boot settings affected?
The described condition specifically requires booting with "nopcid", which disables PCID. Systems not using that boot parameter do not match the stated trigger condition.
What can be done before applying the fix?
Avoid booting affected AMD INVLPGB-capable systems with the "nopcid" parameter. Keeping PCID enabled prevents the described mismatch between a disabled CR4.PCIDE state and broadcast flushing using a non-zero PCID.