{"api_version":"1","generated_at":"2026-09-18T22:03:12+00:00","cve":"CVE-2026-89911","urls":{"html":"https://cve.report/CVE-2026-89911","api":"https://cve.report/api/cve/CVE-2026-89911.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89911","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89911"},"summary":{"title":"KVM: arm64: Correctly cap TLBI Range to the architural limit","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Correctly cap TLBI Range to the architural limit\n\nTLB Invalidation by Range has a fairly powerful way of encoding pretty\nlarge ranges in a small number of bits. This range can be based on an\narbitrary VA, which means it is pretty easy for a guest to generate an\noverflow should the hypervisor be naive enough to add the range to the\nbase...\n\nMake sure the range is capped to the limit dictated by the address bit\nthat determines the VA range. For an IPA invalidation, this is further\ncorrected down the line to ignore the upper range.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:17:00","updated_at":"2026-09-16 15:18:17"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.9","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H","baseScore":7.9,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.9","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H","data":{"baseScore":7.9,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/566b1f08d983615f731cc693f2ad59db302c6b57","name":"https://git.kernel.org/stable/c/566b1f08d983615f731cc693f2ad59db302c6b57","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/69a598288195947a1662b53de702eb6976af96b7","name":"https://git.kernel.org/stable/c/69a598288195947a1662b53de702eb6976af96b7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2de38f0448b45d27eba984fc0d9edb7a138972c2","name":"https://git.kernel.org/stable/c/2de38f0448b45d27eba984fc0d9edb7a138972c2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89911","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89911","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929 566b1f08d983615f731cc693f2ad59db302c6b57 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929 2de38f0448b45d27eba984fc0d9edb7a138972c2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929 69a598288195947a1662b53de702eb6976af96b7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.16","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["arch/arm64/include/asm/kvm_nested.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"566b1f08d983615f731cc693f2ad59db302c6b57","status":"affected","version":"4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929","versionType":"git"},{"lessThan":"2de38f0448b45d27eba984fc0d9edb7a138972c2","status":"affected","version":"4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929","versionType":"git"},{"lessThan":"69a598288195947a1662b53de702eb6976af96b7","status":"affected","version":"4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["arch/arm64/include/asm/kvm_nested.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.16"},{"lessThan":"6.16","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"6.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"6.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.16","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Correctly cap TLBI Range to the architural limit\n\nTLB Invalidation by Range has a fairly powerful way of encoding pretty\nlarge ranges in a small number of bits. This range can be based on an\narbitrary VA, which means it is pretty easy for a guest to generate an\noverflow should the hypervisor be naive enough to add the range to the\nbase...\n\nMake sure the range is capped to the limit dictated by the address bit\nthat determines the VA range. For an IPA invalidation, this is further\ncorrected down the line to ignore the upper range."}],"metrics":[{"cvssV3_1":{"baseScore":7.9,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - A nested arm64 guest reaches decode_range_tlbi() by executing a range TLBI (RVAE/RIPAS2 and related encodings) that traps through kvm_handle_sys_reg into handle_tlbi_el2/handle_ripas2e1is; this is local KVM vCPU execution via /dev/kvm, not a network, adjacent, or physical path.\nAC:L - Once nested virt is available (kvm-arm.mode=nested and KVM_ARM_VCPU_HAS_EL2), the guest fully controls the TLBI operand and can deterministically encode a base+range that overflows the VA half-space; no race or attacker-uncontrollable timing is required.\nPR:L - The attacker must run code in a nested-capable KVM guest or create such a VM through /dev/kvm (typically kvm-group). That is low privilege relative to the host; the emulated TLBI path does not require init-namespace root.\nUI:N - After the nested VM is running, exploitation is triggered solely by the guest executing the range TLBI; no additional host-user or victim action is required.\nS:C - The bug is in KVM’s nested-virtualization TLB/VNCR handling: an L1 TLBI is misapplied by L0, so host-maintained VNCR and related nested MMU state is not invalidated, crossing the guest/hypervisor security boundary.\nC:L - A wrapping range causes missed VNCR invalidation, so L0 may keep using a stale guest page for EL2 sysreg state and expose that bounded nested-hypervisor data to a page L1 believed unmapped (for example reused by L2). This is not an arbitrary host-memory read.\nI:L - The host may keep writing nested EL2 sysreg state through the stale VNCR mapping into a guest page that should have been invalidated, corrupting bounded nested-virt state rather than providing an arbitrary host write or control-flow hijack.\nA:H - Failed range invalidation leaves stale nested translations that can crash or hang the nested hypervisor or L2 workload, and the guest can repeat the TLBI at will, which is a complete availability loss for that nested VM."}]}],"providerMetadata":{"dateUpdated":"2026-09-16T14:40:01.708Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/566b1f08d983615f731cc693f2ad59db302c6b57"},{"url":"https://git.kernel.org/stable/c/2de38f0448b45d27eba984fc0d9edb7a138972c2"},{"url":"https://git.kernel.org/stable/c/69a598288195947a1662b53de702eb6976af96b7"}],"title":"KVM: arm64: Correctly cap TLBI Range to the architural limit","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89911","datePublished":"2026-09-16T10:32:08.598Z","dateReserved":"2026-09-11T19:38:34.774Z","dateUpdated":"2026-09-16T14:40:01.708Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:17:00","lastModifiedDate":"2026-09-16 15:18:17","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H","baseScore":7.9,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2,"impactScore":5.3}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89911","Ordinal":"1","Title":"KVM: arm64: Correctly cap TLBI Range to the architural limit","CVE":"CVE-2026-89911","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89911","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Correctly cap TLBI Range to the architural limit\n\nTLB Invalidation by Range has a fairly powerful way of encoding pretty\nlarge ranges in a small number of bits. This range can be based on an\narbitrary VA, which means it is pretty easy for a guest to generate an\noverflow should the hypervisor be naive enough to add the range to the\nbase...\n\nMake sure the range is capped to the limit dictated by the address bit\nthat determines the VA range. For an IPA invalidation, this is further\ncorrected down the line to ignore the upper range.","Type":"Description","Title":"KVM: arm64: Correctly cap TLBI Range to the architural limit"}]}}}