{"id":"CVE-2026-98283","summary":"KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()\n\nkvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops\nmmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a\nreference on the kvm_nested_guest pointer obtained from the IDR.  A\nconcurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race\nthrough kvmhv_flush_nested() -\u003e kvmhv_remove_nested() -\u003e idr_remove /\n--refcnt -\u003e kvmhv_release_nested() -\u003e kfree(gp) in that window, leaving\nthe iterating vCPU with a dangling pointer.  The subsequent\nmutex_lock(&gp-\u003etlb_lock) and accesses to gp-\u003eshadow_pgtable,\ngp-\u003eshadow_lpid and gp-\u003el1_host all touch freed memory.  The free path\nis fully L1-controlled.\n\nFix this by incrementing gp-\u003erefcnt inside the loop before dropping\nmmu_lock, mirroring what kvmhv_get_nested() does, and releasing the\nreference with kvmhv_put_nested() after the per-guest work completes.\nThis is the same get/put discipline already used at every other\ncall site that drops mmu_lock while holding a nested-guest pointer.","modified":"2026-10-07T02:47:30.395709439Z","published":"2026-10-06T08:45:44.593Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98283.json"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/24b634852413229bb8340d908b115c3365f3a247"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4d8f7b1f586375df8bce23a0909566ad5e852259"},{"type":"WEB","url":"https://git.kernel.org/stable/c/51938dfa8a51a4f85328413fca9b6e21f9d2d088"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e37fba1ba69385cff2d0e60b371ee19e7d1852d1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ec2d7a52b3996ae81131617b4afc0af31583c1b4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fbf69b7d0555ee83c871f58750770f74b7179ad1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98283.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98283"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"e3b6b4661527e821ffbe3db83952fdb1e6e47c49"},{"fixed":"4d8f7b1f586375df8bce23a0909566ad5e852259"},{"fixed":"e37fba1ba69385cff2d0e60b371ee19e7d1852d1"},{"fixed":"24b634852413229bb8340d908b115c3365f3a247"},{"fixed":"fbf69b7d0555ee83c871f58750770f74b7179ad1"},{"fixed":"ec2d7a52b3996ae81131617b4afc0af31583c1b4"},{"fixed":"51938dfa8a51a4f85328413fca9b6e21f9d2d088"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98283.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.20.0"},{"fixed":"6.1.189"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98283.json"}}],"schema_version":"1.9.0"}