CVE-2026-98164 — In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tra…
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are shared across all address spaces. With SMM, a GFN can therefore be write-tracked in one address space and appear untracked through the other. Check the supplied slot first, then the slot for the other address space. This ensures all callers honor write tracking regardless of the active address space. In particular, it prevents mmu_try_to_unsync_pages() from marking an upper-level shadow page unsync and eventually triggering the BUG in pte_list_remove(). [invert direction of the conditional. - Paolo]
CVSS v3.1 base metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
Low
Attack Complexity
PR
Low
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
None
Confidentiality
I
None
Integrity
A
High
Availability
Affected
- Vendor
- linux
- Product
- linux kernel
Versions
- >= 4.2, < 6.1.187
- >= 6.2, < 6.6.156
- >= 6.7, < 6.12.108
- >= 6.13, < 6.18.49
- >= 6.19, < 7.1.13
- 7.2
Stated as the source expressed them.
References
- patchPatchhttps://git.kernel.org/stable/c/09aa68552d2542cc6c23edd1568ac265dc5d886f
- patchPatchhttps://git.kernel.org/stable/c/0f38453cdb2e17566ccb7c0f3dabd5bd21caca26
- patchPatchhttps://git.kernel.org/stable/c/429b6f43b4d8c98988fdca99e02dc156134e3d77
- patchPatchhttps://git.kernel.org/stable/c/c0a9bd5fca0b5f2dea32b0fc31350e71e8648112
- patchPatchhttps://git.kernel.org/stable/c/d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212a
- patchPatchhttps://git.kernel.org/stable/c/ec8fcaf354c1cbb36755d48e9f5a00c9591349e5
Related threats
same CWE or vendorCVE-2026-107284 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.
CVE-2026-107284 · 1d ago
CVE-2026-106586 — In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a differe…
CVE-2026-106586 · 2d ago
CVE-2026-102124 — A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration.
CVE-2026-102124 · 8d ago
CVE-2026-102110 — An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so du…
CVE-2026-102110 · 8d ago
CVE-2026-96760 — Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability.
CVE-2026-96760 · 10d ago
CVE-2026-98163 — In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb9…
CVE-2026-98163 · 13d ago