{"id":"AZL-106359","summary":"CVE-2026-98283 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()\n\nkvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops\nmmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a\nreference on the kvm_nested_guest pointer obtained from the IDR.  A\nconcurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race\nthrough kvmhv_flush_nested() -\u003e kvmhv_remove_nested() -\u003e idr_remove /\n--refcnt -\u003e kvmhv_release_nested() -\u003e kfree(gp) in that window, leaving\nthe iterating vCPU with a dangling pointer.  The subsequent\nmutex_lock(&gp-\u003etlb_lock) and accesses to gp-\u003eshadow_pgtable,\ngp-\u003eshadow_lpid and gp-\u003el1_host all touch freed memory.  The free path\nis fully L1-controlled.\n\nFix this by incrementing gp-\u003erefcnt inside the loop before dropping\nmmu_lock, mirroring what kvmhv_get_nested() does, and releasing the\nreference with kvmhv_put_nested() after the per-guest work completes.\nThis is the same get/put discipline already used at every other\ncall site that drops mmu_lock while holding a nested-guest pointer.","modified":"2026-10-07T14:17:02.010770127Z","published":"2026-10-06T09:18:18Z","upstream":["CVE-2026-98283"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98283"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106359.json"}}],"schema_version":"1.9.0"}