Improper initialization in Linux kernel - CVE-2026-89932
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to disclose or modify sensitive information, or cause a denial of service.
The vulnerability exists due to improper initialization of last_vpid in KVM nested VMX VPID management when reusing a VPID after an L1 guest transitions from VMXOFF to VMXON and runs an L2 guest. A local user can cause stale TLB entries associated with a previous VPID lifetime to be used to disclose or modify sensitive information, or cause a denial of service.
Affected software
How to mitigate CVE-2026-89932
External References
- https://git.kernel.org/stable/c/121991d150735f3c0f7401678ce4d35c5b4ac898
- https://git.kernel.org/stable/c/22dfcc22c95e91295119a1c3b469816ce44c4804
- https://git.kernel.org/stable/c/26de0d2d9a8d14c03e5ebb25fd68b5bfcd5ac366
- https://git.kernel.org/stable/c/62604376c313178811375f40a282fc2a46cd2311
- https://git.kernel.org/stable/c/8b98d662ab24f34710a56e03bc9169e4a5508606
- https://git.kernel.org/stable/c/8bc609999ec223089fec8d74c7de27d689606b36
- https://git.kernel.org/stable/c/f0772389413dce9657c7d6950abf3edbbd511356