{"id":"CVE-2026-89914","published":"2026-09-16T11:17:00.443","lastModified":"2026-09-16T15:18:17.647","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Sign-extend VA for range-based TLBI invalidation\n\nWhen the decode_range_tlbi() helper was moved to be used for S1 TLBIs,\nthe required sign extension was omitted. Add it.\n\nAs a result, special care must be taken to not overflow PA bits when\nthis is used for S2 invalidation.","cvssScore":9.3,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/2393470085649f0b973ecceb26fe8fc71edde0c1","tags":[]},{"url":"https://git.kernel.org/stable/c/3feb83918e30f0472e058224b926ebfe8a064fac","tags":[]},{"url":"https://git.kernel.org/stable/c/72bce82c4171bf330919ff1b64dc0a36c254ec7d","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability in the Linux kernel's KVM arm64 implementation allows attackers to perform range-based TLBI invalidation without proper sign extension, potentially leading to privilege escalation.","exploitability":"Exploitation requires specific kernel configuration and access to the affected system. The vulnerability is difficult to exploit without detailed knowledge of the system and the exact conditions under which it can be triggered.","blast_radius":"If exploited, the impact could be severe, potentially allowing an attacker to gain full control over the system or virtual machine.","remediation":"Upgrade to the fixed version 5.19.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["kernel","privilege-escalation","arm64","kvm"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:05:03.781Z"}}