Incorrect Conversion between Numeric Types in Linux kernel - CVE-2026-89775
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to incorrect conversion of a negative mapping level to an unsigned value in the arm64 KVM nested virtualization TLB size evaluation logic when evaluating VNCR TLB invalidation with the S1 MMU disabled. A remote attacker can trigger TLB invalidation evaluation using an S1 MMU-disabled mapping level to compromise confidentiality, integrity, and availability.