{"api_version":"1","generated_at":"2026-09-17T06:06:34+00:00","cve":"CVE-2026-89908","urls":{"html":"https://cve.report/CVE-2026-89908","api":"https://cve.report/api/cve/CVE-2026-89908.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89908","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89908"},"summary":{"title":"LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY\n\nkvm_arch_prepare_memory_region() computes new->arch.flags, i.e. whether\na memslot is KVM_MEM_HUGEPAGE_CAPABLE or KVM_MEM_HUGEPAGE_INCAPABLE,\nonly for KVM_MR_CREATE and KVM_MR_MOVE, and returns early for every\nother change. But the generic code allocates a zeroed memslot for every\nchange and never copies old->arch, so after a KVM_MR_FLAGS_ONLY update,\ne.g. toggling KVM_MEM_LOG_DIRTY_PAGES for live migration, the active\nmemslot has arch.flags == 0.\n\nWith both flags clear, fault_supports_huge_mapping() falls through to\nthe alignment check on the HVA range alone, which no longer verifies\nthat the GPA and HVA have the same offset within a PMD. A memslot that\nwas marked KVM_MEM_HUGEPAGE_INCAPABLE because of a GPA/HVA offset\nmismatch can then be mapped with PMD entries on read faults, and since\nkvm_map_page() aligns the gfn and the pfn independently, the guest ends\nup accessing the wrong host pages, exactly the \"d -> f, e -> g\" case\ndescribed in the comment above the check.\n\nCarry the arch flags over from the old memslot for KVM_MR_FLAGS_ONLY,\nas the GPA, HVA and size are guaranteed to be unchanged for that case.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:16:59","updated_at":"2026-09-16 15:18:17"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/bc7a6849b4395f45a602db91b0fb2fb2e9ed4bba","name":"https://git.kernel.org/stable/c/bc7a6849b4395f45a602db91b0fb2fb2e9ed4bba","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4e4dbc341b1581dc512b85d98b768373b0398366","name":"https://git.kernel.org/stable/c/4e4dbc341b1581dc512b85d98b768373b0398366","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/27a9bfee3bbcb3cabb77797354f07e0e44e49831","name":"https://git.kernel.org/stable/c/27a9bfee3bbcb3cabb77797354f07e0e44e49831","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7c6df65b53846cd7a9a1c81c6ddb42fdc08603e8","name":"https://git.kernel.org/stable/c/7c6df65b53846cd7a9a1c81c6ddb42fdc08603e8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89908","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89908","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7ab6fb505b2a7447c4a7237a12c59e3ad0c7298c 7c6df65b53846cd7a9a1c81c6ddb42fdc08603e8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7ab6fb505b2a7447c4a7237a12c59e3ad0c7298c 4e4dbc341b1581dc512b85d98b768373b0398366 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7ab6fb505b2a7447c4a7237a12c59e3ad0c7298c bc7a6849b4395f45a602db91b0fb2fb2e9ed4bba git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7ab6fb505b2a7447c4a7237a12c59e3ad0c7298c 27a9bfee3bbcb3cabb77797354f07e0e44e49831 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.8","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["arch/loongarch/kvm/mmu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"7c6df65b53846cd7a9a1c81c6ddb42fdc08603e8","status":"affected","version":"7ab6fb505b2a7447c4a7237a12c59e3ad0c7298c","versionType":"git"},{"lessThan":"4e4dbc341b1581dc512b85d98b768373b0398366","status":"affected","version":"7ab6fb505b2a7447c4a7237a12c59e3ad0c7298c","versionType":"git"},{"lessThan":"bc7a6849b4395f45a602db91b0fb2fb2e9ed4bba","status":"affected","version":"7ab6fb505b2a7447c4a7237a12c59e3ad0c7298c","versionType":"git"},{"lessThan":"27a9bfee3bbcb3cabb77797354f07e0e44e49831","status":"affected","version":"7ab6fb505b2a7447c4a7237a12c59e3ad0c7298c","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["arch/loongarch/kvm/mmu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.8"},{"lessThan":"6.8","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"6.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"6.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"6.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc2","versionStartIncluding":"6.8","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY\n\nkvm_arch_prepare_memory_region() computes new->arch.flags, i.e. whether\na memslot is KVM_MEM_HUGEPAGE_CAPABLE or KVM_MEM_HUGEPAGE_INCAPABLE,\nonly for KVM_MR_CREATE and KVM_MR_MOVE, and returns early for every\nother change. But the generic code allocates a zeroed memslot for every\nchange and never copies old->arch, so after a KVM_MR_FLAGS_ONLY update,\ne.g. toggling KVM_MEM_LOG_DIRTY_PAGES for live migration, the active\nmemslot has arch.flags == 0.\n\nWith both flags clear, fault_supports_huge_mapping() falls through to\nthe alignment check on the HVA range alone, which no longer verifies\nthat the GPA and HVA have the same offset within a PMD. A memslot that\nwas marked KVM_MEM_HUGEPAGE_INCAPABLE because of a GPA/HVA offset\nmismatch can then be mapped with PMD entries on read faults, and since\nkvm_map_page() aligns the gfn and the pfn independently, the guest ends\nup accessing the wrong host pages, exactly the \"d -> f, e -> g\" case\ndescribed in the comment above the check.\n\nCarry the arch flags over from the old memslot for KVM_MR_FLAGS_ONLY,\nas the GPA, HVA and size are guaranteed to be unchanged for that case."}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached from a LoongArch KVM guest page fault on the host KVM_RUN path (kvm_arch_vcpu_ioctl_run -> kvm_handle_exit -> kvm_handle_fault -> kvm_handle_mm_fault -> kvm_map_page) after KVM_SET_USER_MEMORY_REGION FLAGS_ONLY; there is no network or physical path.\nAC:L - After FLAGS_ONLY zeros memslot arch.flags, a guest load to an interior GPA of a GPA/HVA-offset-mismatched slot with host THP backing deterministically installs a PMD because kvm_map_page aligns gfn and pfn independently; the VMM chooses the memslot and dirty-log toggle, and THP is a common default, not a rare config or uncontrolled race.\nPR:L - A tenant guest or a host kvm-group user running QEMU is sufficient: /dev/kvm and kvm_vm_ioctl() have no capable() check, and the fault path has none either. Init-namespace root is not required, so this is Low rather than High.\nUI:N - The attacker guest issues the faulting load or store itself during KVM_RUN; no separate victim action such as mounting a filesystem, opening a crafted file, or confirming a prompt is required.\nS:C - kvm_map_page installs stage-2 PMD entries that bind guest GPAs to the wrong host PFNs, breaking the hypervisor GPA-to-HVA contract and crossing the KVM guest-to-host isolation boundary, which CNA guidance rates Changed for KVM guest-to-host escape.\nC:H - On read faults, fault_supports_huge_mapping() allows a PMD that maps the guest onto the wrong host pages (the commit's d->f, e->g case), giving the guest an unauthorized read of the host physical pages backing that 2MB block.\nI:H - After dirty logging is toggled off (another FLAGS_ONLY that also leaves arch.flags at 0), write faults install writable huge mappings to those same wrong host PFNs, so the guest can modify host pages the memslot did not bind to that GPA.\nA:H - Aliased stage-2 PMDs scramble guest RAM and, during live migration, produce a corrupted destination image that can crash the VM; incorrect huge PFNs can also oops the host if the aligned range is not valid RAM, denying service to the hypervisor and co-located VMs."}]}],"providerMetadata":{"dateUpdated":"2026-09-16T14:39:58.684Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/7c6df65b53846cd7a9a1c81c6ddb42fdc08603e8"},{"url":"https://git.kernel.org/stable/c/4e4dbc341b1581dc512b85d98b768373b0398366"},{"url":"https://git.kernel.org/stable/c/bc7a6849b4395f45a602db91b0fb2fb2e9ed4bba"},{"url":"https://git.kernel.org/stable/c/27a9bfee3bbcb3cabb77797354f07e0e44e49831"}],"title":"LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89908","datePublished":"2026-09-16T10:32:06.599Z","dateReserved":"2026-09-11T19:38:34.774Z","dateUpdated":"2026-09-16T14:39:58.684Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:16:59","lastModifiedDate":"2026-09-16 15:18:17","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2,"impactScore":6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89908","Ordinal":"1","Title":"LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY","CVE":"CVE-2026-89908","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89908","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY\n\nkvm_arch_prepare_memory_region() computes new->arch.flags, i.e. whether\na memslot is KVM_MEM_HUGEPAGE_CAPABLE or KVM_MEM_HUGEPAGE_INCAPABLE,\nonly for KVM_MR_CREATE and KVM_MR_MOVE, and returns early for every\nother change. But the generic code allocates a zeroed memslot for every\nchange and never copies old->arch, so after a KVM_MR_FLAGS_ONLY update,\ne.g. toggling KVM_MEM_LOG_DIRTY_PAGES for live migration, the active\nmemslot has arch.flags == 0.\n\nWith both flags clear, fault_supports_huge_mapping() falls through to\nthe alignment check on the HVA range alone, which no longer verifies\nthat the GPA and HVA have the same offset within a PMD. A memslot that\nwas marked KVM_MEM_HUGEPAGE_INCAPABLE because of a GPA/HVA offset\nmismatch can then be mapped with PMD entries on read faults, and since\nkvm_map_page() aligns the gfn and the pfn independently, the guest ends\nup accessing the wrong host pages, exactly the \"d -> f, e -> g\" case\ndescribed in the comment above the check.\n\nCarry the arch flags over from the old memslot for KVM_MR_FLAGS_ONLY,\nas the GPA, HVA and size are guaranteed to be unchanged for that case.","Type":"Description","Title":"LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY"}]}}}