Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19574— ARM64 MMU can assign an in-use ASID to a new memory domain, breaking user-mode memory isolation

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ARM64 MMU 后端在 (位于 )中,使用简单的循环计数器(bare round-robin counter)为内存域分配地址空间标识符(ASIDs)。由于 设置为 8,因此总共只有 255 个可用的 ASID。一旦计数器发生回绕(wrap), 可能会将一个已被当前存活域占用的 ASID 分配给一个新的域。由于域私有映射是以非全局方式(MT_NG)安装的,ASID 成为 TLB 中区分不同域的缓存翻译条目的唯一标签。 在上下文切换路径 中,仅当退出域和进入域具有相同的 ASID 时才会刷新 TLB。这一机制未能

CVSS 7.0 · High

Possible ATT&CK Techniques 1 AI

T1079
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19574

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ARM64 MMU can assign an in-use ASID to a new memory domain, breaking user-mode memory isolation
Source: CVE Program / CVE List V5
Vulnerability Description
The ARM64 MMU back-end allocated address space identifiers (ASIDs) for memory domains with a bare round-robin counter in arch_mem_domain_init() (arch/arm64/core/mmu.c). VM_ASID_BITS is 8, so only 255 ASIDs exist; once the counter wrapped, arch_mem_domain_init() could hand an ASID to a new domain while a still-live domain held the same one. Domain-private mappings are installed non-global (MT_NG), so the ASID is the only tag separating one domain's cached translations from another's in the TLB. The context-switch path in z_arm64_swap_ptables() only flushes the TLB when the outgoing and incoming domains carry the same ASID, which does not cover a duplicate reached through a third domain: for domains A and C sharing an ASID and an unrelated domain B, the schedule A -> B -> C never takes the flush branch, so the ASID-tagged entries A populated remain resident while C runs. Under SMP two live domains sharing an ASID can additionally be resident on two CPUs at once, which the architecture does not allow for distinct translation-table sets. Triggering the wrap requires a CONFIG_USERSPACE application on ARM64 that creates more than 255 memory domains over its lifetime; k_mem_domain_init() and k_mem_domain_deinit() are supervisor-only APIs and are not exposed as syscalls, so an unprivileged thread cannot drive the counter directly. Once two live domains alias, however, a user-mode thread in one domain can read and write memory belonging to the other domain's partitions and thread stacks with that domain's permissions, defeating the memory-domain isolation boundary. The fix scans the live domain_list before assigning an ASID, advances the round-robin counter past ASIDs already in use, and returns -ENOMEM when all are taken, so domain creation fails closed instead of silently aliasing.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 3.3.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-19574

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19574

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-19574 (1)

Vendor Advisories for CVE-2026-19574 (1)

Same Patch Batch · zephyrproject · 2026-10-09 · 5 CVEs total

CVE-2026-19570 8.8 HIGH Out-of-bounds write in LE Audio Broadcast Sink when copying BASE subgroup metadata into th
CVE-2026-19569 8.8 HIGH Integer overflow in dynamic kernel object allocation allows user-mode threads to corrupt t
CVE-2026-19575 7.8 HIGH Type confusion in the device_deinit system call allows user-mode threads to execute arbitr
CVE-2026-19571 6.7 MEDIUM Race condition in ITE IT8xxx2 SHI host-command backend lets a second SPI request write an

IV. Related Vulnerabilities

V. Comments for CVE-2026-19574

No comments yet


Leave a comment