{"id":"CVE-2026-89912","summary":"KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save\n\nMAPC with V=0 drops ite-\u003ecollection but leaves the ITE on the device's\nITT list, and vgic_its_save_ite() dereferences it unconditionally. A\nguest that issues MAPD, MAPTI and then MAPC(V=0) therefore oopses the\nhost when the VMM issues KVM_DEV_ARM_ITS_SAVE_TABLES to migrate it.\nThat sequence is UNPREDICTABLE per the architecture, but KVM already\nhandles the resulting state in the translate, MOVI and DISCARD paths.\n\nSave a zeroed entry, which vgic_its_restore_ite() reads back as\ninvalid. Skipping the ITE instead would leave the ITT slot holding\nwhatever is in guest memory, and restore rejects an entry naming a\ncollection the restored collection table does not have.","modified":"2026-09-17T03:47:27.182081758Z","published":"2026-09-16T10:32:09.272Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89912.json"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/36df368861d2664291298feeb37dfef43fcae670"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3d4c26b16a04a084fe0bde08ccdd8086570f8bbe"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c6c156d931c33b92362383cf76f6d6e1291dcbfe"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89912.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89912"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"eff484e0298da5a4d18ca82f5454c557fd942af5"},{"fixed":"3d4c26b16a04a084fe0bde08ccdd8086570f8bbe"},{"fixed":"36df368861d2664291298feeb37dfef43fcae670"},{"fixed":"c6c156d931c33b92362383cf76f6d6e1291dcbfe"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89912.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.12.0"},{"fixed":"6.18.51"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89912.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"}]}