CVE-2026-98164
Last modified
CVE-2026-98164 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are shared across all address spaces. With SMM, a GFN can therefore be write-tracked in one address space and appear untracked through the other. Check the supplied slot first, then the slot for the other address space. This ensures all callers honor write tracking regardless of the active address space.
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are shared across all address spaces. With SMM, a GFN can therefore be write-tracked in one address space and appear untracked through the other. Check the supplied slot first, then the slot for the other address space. This ensures all callers honor write tracking regardless of the active address space. In particular, it prevents mmu_try_to_unsync_pages() from marking an upper-level shadow page unsync and eventually triggering the BUG in pte_list_remove(). [invert direction of the conditional. - Paolo]
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 699023e239658e62da6f42f47d31b54788521ec1, < 09aa68552d2542cc6c23edd1568ac265dc5d886f; >= 699023e239658e62da6f42f47d31b54788521ec1, < 429b6f43b4d8c98988fdca99e02dc156134e3d77; >= 699023e239658e62da6f42f47d31b54788521ec1, < d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212a; >= 699023e239658e62da6f42f47d31b54788521ec1, < c0a9bd5fca0b5f2dea32b0fc31350e71e8648112; >= 699023e239658e62da6f42f47d31b54788521ec1, < ec8fcaf354c1cbb36755d48e9f5a00c9591349e5; >= 699023e239658e62da6f42f47d31b54788521ec1, < 0f38453cdb2e17566ccb7c0f3dabd5bd21caca26 |
| Linux | Linux | 4.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-98164?
How severe is CVE-2026-98164?
How do I fix CVE-2026-98164?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-98159In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9816Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 1…8.3
- CVE-2026-98160In the Linux kernel, the following vulnerability has been re…
- CVE-2026-98161In the Linux kernel, the following vulnerability has been re…
- CVE-2026-98162In the Linux kernel, the following vulnerability has been re…
- CVE-2026-98163In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9818Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-9820Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fa…3.8
- CVE-2026-9822The WP Hotel Booking WordPress plugin before 2.3.1 does not …6.5
- CVE-2026-9824Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.1…4.3
- CVE-2026-9828Deserialization of untrusted data vulnerability in QOS.CH Sa…2.9
- CVE-2026-9829The Photo Gallery by 10Web – Mobile-Friendly Image Gallery p…6.5
Are you affected by CVE-2026-98164?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
