
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98164 is a kernel denial-of-service vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) x86 MMU subsystem, specifically in the write-tracking logic for guest physical address spaces. The flaw exists because kvm_gfn_is_write_tracked() checks only the supplied memslot rather than all address spaces, allowing a guest frame number (GFN) to appear untracked when accessed through a different address space (e.g., SMM vs. non-SMM). This inconsistency can trigger a kernel BUG in pte_list_remove(), causing a host kernel panic. The vulnerability affects Linux kernel versions from 4.2 onward (introduced at commit 699023e239658e62da6f42f47d31b54788521ec1) and was disclosed on September 29, 2026. It carries a CVSS estimate of Medium severity (Red Hat Advisory, Feedly).
The root cause is classified as CWE-617 (Reachable Assertion): page write tracking in KVM is maintained per-address-space, but shadow pages are shared across all address spaces. When System Management Mode (SMM) is active, a GFN can be write-tracked in the SMM address space but appear untracked when queried through the non-SMM address space (or vice versa), because kvm_gfn_is_write_tracked() only inspects the memslot passed to it. This allows mmu_try_to_unsync_pages() to incorrectly mark an upper-level shadow page as unsync, eventually reaching a BUG assertion in pte_list_remove(). The fix checks the supplied slot first, then the slot for the other address space, ensuring consistent write-tracking enforcement across all callers (Red Hat Advisory, GitHub Advisory).
Successful exploitation causes a host kernel panic (denial of service), crashing the KVM hypervisor and all virtual machines running on it. The impact is limited to availability — there is no evidence of confidentiality or integrity compromise. Because the crash affects the host kernel, all tenants sharing the same physical host in a multi-tenant virtualization environment would be disrupted simultaneously, making this particularly impactful in cloud or shared hosting scenarios (Feedly, Red Hat Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Feedly). Exploitation requires local access to a KVM host with the ability to create or control virtual machines, and SMM must be enabled in the guest configuration. The EPSS score is 0.0, reflecting very low probability of near-term exploitation. This CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (Red Hat Advisory).
dmesg, /var/log/kern.log) showing a kernel BUG or panic originating from pte_list_remove() or related KVM MMU functions (e.g., mmu_try_to_unsync_pages).Apply the kernel patches backported to the following stable branches: 6.1.187, 6.6.156, 6.12.108, 6.18.49, 7.1.13, and 7.2 (mainline). The fix commits are available in the Linux stable kernel repository. As a workaround where patching is not immediately feasible, restrict unprivileged user access to KVM virtual machine creation, and consider disabling SMM in guest configurations if operationally acceptable. Monitor systems for unexpected kernel panics related to KVM page tracking (Red Hat Advisory, GitHub Advisory).
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
linux
bionic (fips-updates)
linux-fips
bionic (fips)
linux-fips
devel
linux
focal (esm-infra)
linux
focal (fips-updates)
linux-fips
focal (fips)
linux-fips
jammy
linux
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."