CVE-2026-98283: KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

KVM: PPC: Book3S HV: fix use-after-free in kvmhvemulatetlbiealllpid()

kvmhvemulatetlbiealllpid() iterates the nested-guest IDR and drops mmulock before calling kvmhvemulatetlbielpid(), but does not hold a reference on the kvmnestedguest pointer obtained from the IDR. A concurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race through kvmhvflushnested() -> kvmhvremovenested() -> idrremove / --refcnt -> kvmhvreleasenested() -> kfree(gp) in that window, leaving the iterating vCPU with a dangling pointer. The subsequent mutexlock(&gp->tlblock) and accesses to gp->shadowpgtable, gp->shadowlpid and gp->l1host all touch freed memory. The free path is fully L1-controlled.

Fix this by incrementing gp->refcnt inside the loop before dropping mmulock, mirroring what kvmhvgetnested() does, and releasing the reference with kvmhvputnested() after the per-guest work completes. This is the same get/put discipline already used at every other call site that drops mmulock while holding a nested-guest pointer.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In kvmhv_emulate_tlbie_all_lpid(), increment gp->refcnt for each nested-guest pointer before dropping mmu_lock, then call kvmhv_put_nested() after kvmhv_emulate_tlbie_lpid() and the per-guest work completes.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionSeverity
Data Sourced
via NVD·09:18 AM
DescriptionSeverity
Oct 7, 2026
Data Sourced
via Microsoft·08:13 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are exposed to this flaw?

The issue affects Linux kernel deployments using KVM on PowerPC Book3S HV with nested guests. Systems not using that KVM virtualization configuration are not indicated as affected by the provided information.

2

What is required to trigger the use-after-free?

A concurrent vCPU must issue a single-LPID tlbie with is=2 and ric=2 while another vCPU follows the nested-guest removal path. The nested-guest free path is fully controlled by the L1 guest.

3

What is the impact if the race occurs?

The iterating vCPU can retain a dangling nested-guest pointer and subsequently lock or access fields in freed memory, including tlb_lock, shadow_pgtable, shadow_lpid, and l1_host. The CVSS vector indicates local, low-complexity exploitation with low privileges and impacts to confidentiality, integrity, and availability across a changed security scope.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203