Integer overflow in Linux kernel - CVE-2026-89911
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service and compromise confidentiality and integrity.
The vulnerability exists due to an integer overflow in the KVM arm64 TLBI range decoder when processing guest TLB invalidation by range operations. A local user can generate a TLB invalidation range that overflows when added to its base address to cause a denial of service and compromise confidentiality and integrity.