8.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Reassign nested_mmus array behind mmu_lock
kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the
MMU notifier path (kvm_unmap_gfn_range() -> kvm_nested_s2_unmap()), which
can run at any time. kvm_vcpu_init_nested() reallocates the array and frees
the old buffer while holding only kvm->arch.config_lock, so such a walker
can reference the freed array.
Allocate the new array outside of mmu_lock, as the allocation can sleep.
Under the lock, copy the existing entries, fix up the back pointers and
reassign the array. Free the old buffer after dropping the lock, as
kvfree() can sleep as well.
KVM: arm64: Reassign nested_mmus array behind mmu_lock
kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the
MMU notifier path (kvm_unmap_gfn_range() -> kvm_nested_s2_unmap()), which
can run at any time. kvm_vcpu_init_nested() reallocates the array and frees
the old buffer while holding only kvm->arch.config_lock, so such a walker
can reference the freed array.
Allocate the new array outside of mmu_lock, as the allocation can sleep.
Under the lock, copy the existing entries, fix up the back pointers and
reassign the array. Free the old buffer after dropping the lock, as
kvfree() can sleep as well.
AI Analysis
Use-after-free vulnerability in KVM: arm64 due to incorrect handling of nested_mmus array behind mmu_lock
Basic Information
ID
CVE-2026-46317
Source
Linux
Published
Jun 9, 2026 at 11:52
Modified
Jun 14, 2026 at 04:30
Affected Product
Vendor
Linux
Product
Linux
Version
4f128f8e1aaac189f83d0f828bcdb2986d8d2e51
Affected Versions
Linux Linux 4f128f8e1aaac189f83d0f828bcdb2986d8d2e51
Linux Linux 4f128f8e1aaac189f83d0f828bcdb2986d8d2e51
Linux Linux 4f128f8e1aaac189f83d0f828bcdb2986d8d2e51
Linux Linux 6.11
Linux Linux 4f128f8e1aaac189f83d0f828bcdb2986d8d2e51
Linux Linux 4f128f8e1aaac189f83d0f828bcdb2986d8d2e51
Linux Linux 6.11
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Linux
Product
Linux Kernel
Version
6.11, 4f128f8e1aaac189f83d0f828bcdb2986d8d2e51