{"api_version":"1","generated_at":"2026-09-26T13:05:30+00:00","cve":"CVE-2026-89912","urls":{"html":"https://cve.report/CVE-2026-89912","api":"https://cve.report/api/cve/CVE-2026-89912.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89912","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89912"},"summary":{"title":"KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save\n\nMAPC with V=0 drops ite->collection but leaves the ITE on the device's\nITT list, and vgic_its_save_ite() dereferences it unconditionally. A\nguest that issues MAPD, MAPTI and then MAPC(V=0) therefore oopses the\nhost when the VMM issues KVM_DEV_ARM_ITS_SAVE_TABLES to migrate it.\nThat sequence is UNPREDICTABLE per the architecture, but KVM already\nhandles the resulting state in the translate, MOVI and DISCARD paths.\n\nSave a zeroed entry, which vgic_its_restore_ite() reads back as\ninvalid. Skipping the ITE instead would leave the ITT slot holding\nwhatever is in guest memory, and restore rejects an entry naming a\ncollection the restored collection table does not have.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:17:00","updated_at":"2026-09-16 15:18:17"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","data":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/36df368861d2664291298feeb37dfef43fcae670","name":"https://git.kernel.org/stable/c/36df368861d2664291298feeb37dfef43fcae670","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3d4c26b16a04a084fe0bde08ccdd8086570f8bbe","name":"https://git.kernel.org/stable/c/3d4c26b16a04a084fe0bde08ccdd8086570f8bbe","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c6c156d931c33b92362383cf76f6d6e1291dcbfe","name":"https://git.kernel.org/stable/c/c6c156d931c33b92362383cf76f6d6e1291dcbfe","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89912","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89912","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected eff484e0298da5a4d18ca82f5454c557fd942af5 3d4c26b16a04a084fe0bde08ccdd8086570f8bbe git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected eff484e0298da5a4d18ca82f5454c557fd942af5 36df368861d2664291298feeb37dfef43fcae670 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected eff484e0298da5a4d18ca82f5454c557fd942af5 c6c156d931c33b92362383cf76f6d6e1291dcbfe git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.12","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.12 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["arch/arm64/kvm/vgic/vgic-its.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"3d4c26b16a04a084fe0bde08ccdd8086570f8bbe","status":"affected","version":"eff484e0298da5a4d18ca82f5454c557fd942af5","versionType":"git"},{"lessThan":"36df368861d2664291298feeb37dfef43fcae670","status":"affected","version":"eff484e0298da5a4d18ca82f5454c557fd942af5","versionType":"git"},{"lessThan":"c6c156d931c33b92362383cf76f6d6e1291dcbfe","status":"affected","version":"eff484e0298da5a4d18ca82f5454c557fd942af5","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["arch/arm64/kvm/vgic/vgic-its.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.12"},{"lessThan":"4.12","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"4.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"4.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"4.12","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save\n\nMAPC with V=0 drops ite->collection but leaves the ITE on the device's\nITT list, and vgic_its_save_ite() dereferences it unconditionally. A\nguest that issues MAPD, MAPTI and then MAPC(V=0) therefore oopses the\nhost when the VMM issues KVM_DEV_ARM_ITS_SAVE_TABLES to migrate it.\nThat sequence is UNPREDICTABLE per the architecture, but KVM already\nhandles the resulting state in the translate, MOVI and DISCARD paths.\n\nSave a zeroed entry, which vgic_its_restore_ite() reads back as\ninvalid. Skipping the ITE instead would leave the ITT slot holding\nwhatever is in guest memory, and restore rejects an entry naming a\ncollection the restored collection table does not have."}],"metrics":[{"cvssV3_1":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The NULL dereference is reached only via the local KVM ioctl KVM_SET_DEVICE_ATTR(KVM_DEV_ARM_ITS_SAVE_TABLES) after the guest programs in-kernel GICv3 ITS MMIO (MAPD/MAPTI/MAPC or GITS_BASER); it is not triggered by network packets, adjacent-radio frames, or a physical device.\nAC:L - A guest can deterministically issue MAPD, MAPTI, then MAPC with V=0, or clear GITS_BASER collection Valid, leaving ITEs on the ITT with a NULL collection; SAVE_TABLES then always dereferences it with no race or attacker-uncontrollable host layout.\nPR:N - The highest-impact case is a cloud VM tenant who needs no host privileges: they program the ITS from guest EL1 and the host oopses when the hypervisor saves ITS tables during automated live migration, without host root, capabilities, or tenant access to /dev/kvm.\nUI:N - No extra victim action is required beyond normal hypervisor operations such as automated live migration or snapshot save that invoke SAVE_TABLES; a local VMM can also issue that ioctl itself.\nS:C - The fault runs in host KVM while saving guest-controlled ITS state, so a host oops/panic takes down the hypervisor and co-resident VMs, crossing the KVM guest-to-host security boundary.\nC:N - vgic_its_save_ite() only loads collection_id through a NULL ite->collection pointer; this is a pure NULL dereference with no out-of-bounds read, use-after-free, or other host disclosure primitive.\nI:N - The NULL collection is read and not written, and the bug does not corrupt host kernel memory, provide an arbitrary write, or hijack host control flow beyond the faulting load.\nA:H - Dereferencing the NULL collection in vgic_its_save_ite() oopses or panics the host kernel during ITS table save, denying service to the hypervisor and every co-located VM."}]}],"providerMetadata":{"dateUpdated":"2026-09-16T14:40:03.242Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/3d4c26b16a04a084fe0bde08ccdd8086570f8bbe"},{"url":"https://git.kernel.org/stable/c/36df368861d2664291298feeb37dfef43fcae670"},{"url":"https://git.kernel.org/stable/c/c6c156d931c33b92362383cf76f6d6e1291dcbfe"}],"title":"KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89912","datePublished":"2026-09-16T10:32:09.272Z","dateReserved":"2026-09-11T19:38:34.774Z","dateUpdated":"2026-09-16T14:40:03.242Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:17:00","lastModifiedDate":"2026-09-16 15:18:17","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":4}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89912","Ordinal":"1","Title":"KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT","CVE":"CVE-2026-89912","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89912","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save\n\nMAPC with V=0 drops ite->collection but leaves the ITE on the device's\nITT list, and vgic_its_save_ite() dereferences it unconditionally. A\nguest that issues MAPD, MAPTI and then MAPC(V=0) therefore oopses the\nhost when the VMM issues KVM_DEV_ARM_ITS_SAVE_TABLES to migrate it.\nThat sequence is UNPREDICTABLE per the architecture, but KVM already\nhandles the resulting state in the translate, MOVI and DISCARD paths.\n\nSave a zeroed entry, which vgic_its_restore_ite() reads back as\ninvalid. Skipping the ITE instead would leave the ITT slot holding\nwhatever is in guest memory, and restore rejects an entry naming a\ncollection the restored collection table does not have.","Type":"Description","Title":"KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT"}]}}}