OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-89914

CRITICAL · CVSS 9.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's KVM component, specifically in the handling of range-based Translation Lookaside Buffer Invalidation (TLBI) for arm64 architecture. The omission of necessary sign extension during the processing of S1 TLBI can lead to potential overflows in physical address bits when applied to S2 invalidation, which may compromise memory integrity. Organizations utilizing Linux systems with KVM on arm64 should prioritize addressing this issue to mitigate risks associated with memory management vulnerabilities.

CVE
CVE-2026-89914
Severity
CRITICAL
CVSS
9.3
EPSS
0.19%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for range-based TLBI invalidation When the decode_range_tlbi() helper was moved to be used for S1 TLBIs, the required sign extension was omitted. Add it. As a result, special care must be taken to not overflow PA bits when this is used for S2 invalidation.