Time-of-check Time-of-use (TOCTOU) Race Condition in Linux kernel - CVE-2026-89917
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a time-of-check to time-of-use race condition in the Arm64 KVM nested virtualization VNCR mapping logic when concurrent VNCR TLB invalidation and vcpu_put() unmapping occur. A local user can trigger the concurrent operations to cause a denial of service.