Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98164— KVM: x86/mmu: Check write tracking in all address spaces

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: KVM: x86/mmu: 在所有地址空间中检查写跟踪(write tracking) 仅检查所提供的内存插槽(memslot),但页面跟踪是按地址空间进行的,而影子页(shadow pages)在所有地址空间之间共享。因此,在使用 SMM(系统管理模式)时,某个 GFN(Guest Frame Number,客户机帧号)可能在一个地址空间中被标记为写跟踪状态,而在另一个地址空间中则显示为未跟踪状态。 正确的做法是:首先检查所提供的插槽,然后检查另一个地址空间对应的插槽

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98164

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
KVM: x86/mmu: Check write tracking in all address spaces
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are shared across all address spaces. With SMM, a GFN can therefore be write-tracked in one address space and appear untracked through the other. Check the supplied slot first, then the slot for the other address space. This ensures all callers honor write tracking regardless of the active address space. In particular, it prevents mmu_try_to_unsync_pages() from marking an upper-level shadow page unsync and eventually triggering the BUG in pte_list_remove(). [invert direction of the conditional. - Paolo]
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 699023e239658e62da6f42f47d31b54788521ec1 ~ 09aa68552d2542cc6c23edd1568ac265dc5d886f -
Linux Linux 4.2 -

II. Public POCs for CVE-2026-98164

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98164

请登录查看更多情报信息。

Other References for CVE-2026-98164 (6)

IV. Related Vulnerabilities

V. Comments for CVE-2026-98164

No comments yet


Leave a comment