KernelScan.io

CRITICAL Introduced in 6.16

kvm arm64 TLBI SignExtension

CVE-2026-89914

CVSS 9.3 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

KernelScan AI8.8HIGH

01

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for range-based TLBI invalidation When the decode_range_tlbi() helper was moved to be used for S1 TLBIs, the required sign extension was omitted. Add it. As a result, special care must be taken to not overflow PA bits when this is used for S2 invalidation.

02

Engine v0.6.0

Risk summary

A guest VM on arm64 KVM with nested virtualization can trigger incorrect TLB invalidation due to missing sign extension, potentially corrupting host TLB state or causing host instability.

Affectedarch/arm64/kvm/sys_regs.c (KVM arm64)

Vulnerability analysis

When a nested guest issues a range-based TLBI invalidation, the decode helper fails to sign-extend the virtual address, causing the base address to be interpreted incorrectly. This can lead to TLB invalidation of unintended memory regions. The fix adds sign extension for the VA and caps the range for stage-2 invalidation to prevent overflow into physical address bits. A guest VM with nested virtualization enabled can trigger this.

03

BranchIntroducedFixed inPatch commit
6.186.166.18.5172bce82c4171
mainline6.167.3-rc1239347008564
7.26.167.2.53feb83918e30