PT-2026-61192 · Linux · Linux
CVE-2026-63875
·
Published
2026-07-19
·
Updated
2026-07-19
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
arm64: tlb: Flush walk cache when unsharing PMD tables
When huge pmd unshare() is called to unshare a PMD table, the
tlb unshare pmd ptdesc() function sets tlb->unshared tables=true
but the aarch64 tlb flush() only checked tlb->freed tables to
determine whether to use TLBF NONE (vae1is, invalidates walk
cache) or TLBF NOWALKCACHE (vale1is, leaf-only).
This caused the stale PMD page table entry to remain in the walk cache
after unshare, potentially leading to incorrect page table walks.
Fix by including unshared tables in the check, so that when
unsharing tables, TLBF NONE is used and the walk cache is properly
invalidated.
Here is the detailed distinction between vae1is and vale1is:
| Instruction Combination | Actual Invalidation Scope |
|---|---|
VAE1IS + TTL=0 | All entries at all levels (full invalidation) |
VAE1IS + TTL=2 (L2) | Non-leaf at Level 0/1 + leaf at Level 2 |
VALE1IS + TTL=0 | Leaf entries at all levels (non-leaf not cleared) |
VALE1IS + TTL=2 (L2) | Leaf entry at Level 2 only |
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux