CVE-2026-98164
KVM: x86/mmu: Check write tracking in all address spaces
No known exploitation. EPSS puts it in the 8th percentile. Fixed versions are out.
What to do
Find your product and version, then upgrade to the build on the right.
- LinuxAffected: ≥ 699023e239658e62da6f42f47d31b54788521ec1, < 09aa68552d2542cc6c23edd1568ac265dc5d886fUpgrade to: 09aa68552d2542cc6c23edd1568ac265dc5d886fAffected: ≥ 699023e239658e62da6f42f47d31b54788521ec1, < 429b6f43b4d8c98988fdca99e02dc156134e3d77Upgrade to: 429b6f43b4d8c98988fdca99e02dc156134e3d77Affected: ≥ 699023e239658e62da6f42f47d31b54788521ec1, < d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212aUpgrade to: d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212aAffected: ≥ 699023e239658e62da6f42f47d31b54788521ec1, < c0a9bd5fca0b5f2dea32b0fc31350e71e8648112Upgrade to: c0a9bd5fca0b5f2dea32b0fc31350e71e8648112 + 2 more branchesStated by: CVE record
Versions as the sources state them. Full version matrix after sign-in
What it is
From the CVE record
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are shared across all address spaces. With SMM, a GFN can therefore be write-tracked in one address space and appear untracked through the other. Check the supplied slot first, then the slot for the other address space. This ensures all callers honor write tracking regardless of the active address space. In particular, it prevents mmu_try_to_unsync_pages() from marking an upper-level shadow page unsync and eventually triggering the BUG in pte_list_remove(). [invert direction of the conditional. - Paolo]
In plain language
No plain-language summary for this CVE yet.
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
0.2% chance of exploitation activity in the next 30 days, which ranks it in the 8th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
6 events over 3 days, from the signal feeds we watch.
- Patch availablerecord updated
- Record updated
- Publishedweakness classified, record updated
Affected products
And 1 more affected product. See all after sign-in
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Scored 5.5 by NVD.
How it is reached
- Attack Vector LocalRequires local access to the vulnerable system (e.g. local login, malicious file)
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required LowRequires basic user-level privileges
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality NoneNo confidentiality impact
- Integrity NoneNo integrity impact
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
Sources
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Linux, not every advisory.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI