CVE 8.8 HIGH

KVM: arm64: Reassign nested_mmus array behind mmu_lock_CVE-2026-46317

8.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Reassign nested_mmus array behind mmu_lock

kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the
MMU notifier path (kvm_unmap_gfn_range() -> kvm_nested_s2_unmap()), which
can run at any time. kvm_vcpu_init_nested() reallocates the array and frees
the old buffer while holding only kvm->arch.config_lock, so such a walker
can reference the freed array.

Allocate the new array outside of mmu_lock, as the allocation can sleep.
Under the lock, copy the existing entries, fix up the back pointers and
reassign the array. Free the old buffer after dropping the lock, as
kvfree() can sleep as well.

AI Analysis

Use-after-free vulnerability in KVM: arm64 due to incorrect handling of nested_mmus array behind mmu_lock

Basic Information

ID CVE-2026-46317
Source Linux
Published Jun 9, 2026 at 11:52
Modified Jun 14, 2026 at 04:30

Affected Product

Vendor Linux
Product Linux
Version 4f128f8e1aaac189f83d0f828bcdb2986d8d2e51
Affected Versions Linux Linux 4f128f8e1aaac189f83d0f828bcdb2986d8d2e51
Linux Linux 4f128f8e1aaac189f83d0f828bcdb2986d8d2e51
Linux Linux 4f128f8e1aaac189f83d0f828bcdb2986d8d2e51
Linux Linux 6.11

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Linux
Product Linux Kernel
Version 6.11, 4f128f8e1aaac189f83d0f828bcdb2986d8d2e51

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.