CVE-2026-89914
9.3 CRITICALPublished 2026-09-16 · Updated 2026-09-16
AI risk analysis
- Summary
- This vulnerability in the Linux kernel's KVM arm64 implementation allows attackers to perform range-based TLBI invalidation without proper sign extension, potentially leading to privilege escalation.
- Exploitability
- Exploitation requires specific kernel configuration and access to the affected system. The vulnerability is difficult to exploit without detailed knowledge of the system and the exact conditions under which it can be triggered.
- Blast radius
- If exploited, the impact could be severe, potentially allowing an attacker to gain full control over the system or virtual machine.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the fixed version 5.19.1 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for range-based TLBI invalidation When the decode_range_tlbi() helper was moved to be used for S1 TLBIs, the required sign extension was omitted. Add it. As a result, special care must be taken to not overflow PA bits when this is used for S2 invalidation.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-89915
- HIGHCVE-2026-17052PoC
- HIGHCVE-2026-64561PoC
- HIGHCVE-2026-64562
- CRITICALCVE-2026-89775
- HIGHCVE-2026-89777
- CRITICALCVE-2026-89918
- HIGHCVE-2026-89959
Related by shared AI tags and CWE weakness class. Browse the full archive.