Improper initialization in Linux kernel - CVE-2026-89908
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper preservation of memslot architecture flags in the LoongArch KVM memory-region handling code when processing a KVM_MR_FLAGS_ONLY memory-region update. A local user can perform a KVM_MR_FLAGS_ONLY update to compromise confidentiality, integrity, and availability.
The issue occurs when guest physical and host virtual address offsets within a PMD differ.