Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-89930
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause stale TLB translations to be used.
The vulnerability exists due to failure to service queued local TLB flush requests in KVM nVMX nested VM-entry handling when a nested VM entry fails after switching to the L2 context. A remote attacker can change L2's VPID and trigger a failed nested VM entry to cause stale TLB translations to be used.
Affected software
How to mitigate CVE-2026-89930
External References
- https://git.kernel.org/stable/c/05a0b701d1089fb57beeb8982f23c3bbafe0fa8b
- https://git.kernel.org/stable/c/1025b938dc439b75c720a568a855a13eeb245686
- https://git.kernel.org/stable/c/312cdb6d8940827dea63a7a52fb714a5049f06d1
- https://git.kernel.org/stable/c/62c3ee4c9f0e2efef5157358b3549e50ede96d73
- https://git.kernel.org/stable/c/c0c66cd575e31218da6a7d104c6ef80b0830b60c
- https://git.kernel.org/stable/c/c43563e7518e65ec6ccaa6a65f84c5af5ca5d379
- https://git.kernel.org/stable/c/f74fccdf4f7fb0780cd84944108d35f3d9dc46a7