CVE Tools

CVE-2026-98164

KVM: x86/mmu: Check write tracking in all address spaces

No known exploitation. EPSS puts it in the 8th percentile. Fixed versions are out.

Published Updated Sources: CVE.org, NVD

What to do

Find your product and version, then upgrade to the build on the right.

  • LinuxAffected: ≥ 699023e239658e62da6f42f47d31b54788521ec1, < 09aa68552d2542cc6c23edd1568ac265dc5d886fUpgrade to: 09aa68552d2542cc6c23edd1568ac265dc5d886fAffected: ≥ 699023e239658e62da6f42f47d31b54788521ec1, < 429b6f43b4d8c98988fdca99e02dc156134e3d77Upgrade to: 429b6f43b4d8c98988fdca99e02dc156134e3d77Affected: ≥ 699023e239658e62da6f42f47d31b54788521ec1, < d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212aUpgrade to: d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212aAffected: ≥ 699023e239658e62da6f42f47d31b54788521ec1, < c0a9bd5fca0b5f2dea32b0fc31350e71e8648112Upgrade to: c0a9bd5fca0b5f2dea32b0fc31350e71e8648112 + 2 more branchesStated by: CVE record

Versions as the sources state them. Full version matrix after sign-in

What it is

From the CVE record

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are shared across all address spaces. With SMM, a GFN can therefore be write-tracked in one address space and appear untracked through the other. Check the supplied slot first, then the slot for the other address space. This ensures all callers honor write tracking regardless of the active address space. In particular, it prevents mmu_try_to_unsync_pages() from marking an upper-level shadow page unsync and eventually triggering the BUG in pte_list_remove(). [invert direction of the conditional. - Paolo]

In plain language

No plain-language summary for this CVE yet.

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS8th
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

0.2% chance of exploitation activity in the next 30 days, which ranks it in the 8th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

6 events over 3 days, from the signal feeds we watch.

  1. Patch availablerecord updated
  2. Record updated
  3. Publishedweakness classified, record updated

Affected products

And 1 more affected product. See all after sign-in

Technical detail

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Scored 5.5 by NVD.

How it is reached

  • Attack Vector LocalRequires local access to the vulnerable system (e.g. local login, malicious file)
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required LowRequires basic user-level privileges
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality NoneNo confidentiality impact
  • Integrity NoneNo integrity impact
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Linux, not every advisory.