{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  arm64/efi: Avoid voluntary preemption with efi_mm installed  Gus reports a bad kernel memory access when using software PAN (CONFIG_ARM64_SW_TTBR0_PAN=y) on a machine with support for EFI runtime services:    Unable to handle kernel access to user memory outside uaccess routines     at virtual address 00000000f322ff30   Mem abort info:     ESR = 0x0000000096000004     FSC = 0x04: level 0 translation fault   Internal error: Oops: 0000000096000004 [#1]  SMP   Workqueue: efi_rts_wq efi_call_rts   pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)   pc : efi_call_rts+0xd8/0x288   Call trace:    efi_call_rts+0xd8/0x288 (P)    process_one_work+0x178/0x4f8    worker_thread+0x194/0x328  This is because the fpsimd context management code called from __efi_fpsimd_begin() can preempt voluntarily, returning later to the EFI code with an incorrect value for TTBR0_EL1 thanks to the deferred mm switching used by the software PAN implementation.  Since EFI runtime services cannot preempt voluntarily and because the fpsimd switching code does not rely on the TTBR0_EL1 mappings, simply reorder the fpsimd switch so that it occurs before we change the page-table.",
  "id": "DEBIAN-CVE-2026-90212",
  "modified": "2026-09-18T04:47:28.589313701Z",
  "published": "2026-09-17T17:17:16.430Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-90212"
    }
  ],
  "upstream": [
    "CVE-2026-90212"
  ]
}