CVE-2026-98283: KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
In the Linux kernel, the following vulnerability has been resolved:
KVM: PPC: Book3S HV: fix use-after-free in kvmhvemulatetlbiealllpid()
kvmhvemulatetlbiealllpid() iterates the nested-guest IDR and drops mmulock before calling kvmhvemulatetlbielpid(), but does not hold a reference on the kvmnestedguest pointer obtained from the IDR. A concurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race through kvmhvflushnested() -> kvmhvremovenested() -> idrremove / --refcnt -> kvmhvreleasenested() -> kfree(gp) in that window, leaving the iterating vCPU with a dangling pointer. The subsequent mutexlock(&gp->tlblock) and accesses to gp->shadowpgtable, gp->shadowlpid and gp->l1host all touch freed memory. The free path is fully L1-controlled.
Fix this by incrementing gp->refcnt inside the loop before dropping mmulock, mirroring what kvmhvgetnested() does, and releasing the reference with kvmhvputnested() after the per-guest work completes. This is the same get/put discipline already used at every other call site that drops mmulock while holding a nested-guest pointer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In kvmhv_emulate_tlbie_all_lpid(), increment gp->refcnt for each nested-guest pointer before dropping mmu_lock, then call kvmhv_put_nested() after kvmhv_emulate_tlbie_lpid() and the per-guest work completes.
Event History
Frequently Asked Questions
Which systems are exposed to this flaw?
The issue affects Linux kernel deployments using KVM on PowerPC Book3S HV with nested guests. Systems not using that KVM virtualization configuration are not indicated as affected by the provided information.
What is required to trigger the use-after-free?
A concurrent vCPU must issue a single-LPID tlbie with is=2 and ric=2 while another vCPU follows the nested-guest removal path. The nested-guest free path is fully controlled by the L1 guest.
What is the impact if the race occurs?
The iterating vCPU can retain a dangling nested-guest pointer and subsequently lock or access fields in freed memory, including tlb_lock, shadow_pgtable, shadow_lpid, and l1_host. The CVSS vector indicates local, low-complexity exploitation with low privileges and impacts to confidentiality, integrity, and availability across a changed security scope.