{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "e3b6b4661527e821ffbe3db83952fdb1e6e47c49"
            },
            {
              "fixed": "4d8f7b1f586375df8bce23a0909566ad5e852259"
            },
            {
              "fixed": "e37fba1ba69385cff2d0e60b371ee19e7d1852d1"
            },
            {
              "fixed": "24b634852413229bb8340d908b115c3365f3a247"
            },
            {
              "fixed": "fbf69b7d0555ee83c871f58750770f74b7179ad1"
            },
            {
              "fixed": "ec2d7a52b3996ae81131617b4afc0af31583c1b4"
            },
            {
              "fixed": "51938dfa8a51a4f85328413fca9b6e21f9d2d088"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.20.0"
            },
            {
              "fixed": "6.1.189"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98283.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()\n\nkvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops\nmmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a\nreference on the kvm_nested_guest pointer obtained from the IDR.  A\nconcurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race\nthrough kvmhv_flush_nested() -\u003e kvmhv_remove_nested() -\u003e idr_remove /\n--refcnt -\u003e kvmhv_release_nested() -\u003e kfree(gp) in that window, leaving\nthe iterating vCPU with a dangling pointer.  The subsequent\nmutex_lock(\u0026gp-\u003etlb_lock) and accesses to gp-\u003eshadow_pgtable,\ngp-\u003eshadow_lpid and gp-\u003el1_host all touch freed memory.  The free path\nis fully L1-controlled.\n\nFix this by incrementing gp-\u003erefcnt inside the loop before dropping\nmmu_lock, mirroring what kvmhv_get_nested() does, and releasing the\nreference with kvmhv_put_nested() after the per-guest work completes.\nThis is the same get/put discipline already used at every other\ncall site that drops mmu_lock while holding a nested-guest pointer.",
  "id": "CVE-2026-98283",
  "modified": "2026-10-08T02:30:49.628977365Z",
  "published": "2026-10-06T08:45:44.593Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/24b634852413229bb8340d908b115c3365f3a247"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/4d8f7b1f586375df8bce23a0909566ad5e852259"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/51938dfa8a51a4f85328413fca9b6e21f9d2d088"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/e37fba1ba69385cff2d0e60b371ee19e7d1852d1"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ec2d7a52b3996ae81131617b4afc0af31583c1b4"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/fbf69b7d0555ee83c871f58750770f74b7179ad1"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98283.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98283"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()"
}