{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()  kvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops mmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a reference on the kvm_nested_guest pointer obtained from the IDR.  A concurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race through kvmhv_flush_nested() -\u003e kvmhv_remove_nested() -\u003e idr_remove / --refcnt -\u003e kvmhv_release_nested() -\u003e kfree(gp) in that window, leaving the iterating vCPU with a dangling pointer.  The subsequent mutex_lock(\u0026gp-\u003etlb_lock) and accesses to gp-\u003eshadow_pgtable, gp-\u003eshadow_lpid and gp-\u003el1_host all touch freed memory.  The free path is fully L1-controlled.  Fix this by incrementing gp-\u003erefcnt inside the loop before dropping mmu_lock, mirroring what kvmhv_get_nested() does, and releasing the reference with kvmhv_put_nested() after the per-guest work completes. This is the same get/put discipline already used at every other call site that drops mmu_lock while holding a nested-guest pointer.",
  "id": "DEBIAN-CVE-2026-98283",
  "modified": "2026-10-07T04:47:38.108501270Z",
  "published": "2026-10-06T09:18:18.333Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98283"
    }
  ],
  "upstream": [
    "CVE-2026-98283"
  ]
}