CVE-2026-98164: 
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-98164 is a kernel denial-of-service vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) x86 MMU subsystem, specifically in the write-tracking logic for guest physical address spaces. The flaw exists because kvm_gfn_is_write_tracked() checks only the supplied memslot rather than all address spaces, allowing a guest frame number (GFN) to appear untracked when accessed through a different address space (e.g., SMM vs. non-SMM). This inconsistency can trigger a kernel BUG in pte_list_remove(), causing a host kernel panic. The vulnerability affects Linux kernel versions from 4.2 onward (introduced at commit 699023e239658e62da6f42f47d31b54788521ec1) and was disclosed on September 29, 2026. It carries a CVSS estimate of Medium severity (Red Hat Advisory, Feedly).

Technical details

The root cause is classified as CWE-617 (Reachable Assertion): page write tracking in KVM is maintained per-address-space, but shadow pages are shared across all address spaces. When System Management Mode (SMM) is active, a GFN can be write-tracked in the SMM address space but appear untracked when queried through the non-SMM address space (or vice versa), because kvm_gfn_is_write_tracked() only inspects the memslot passed to it. This allows mmu_try_to_unsync_pages() to incorrectly mark an upper-level shadow page as unsync, eventually reaching a BUG assertion in pte_list_remove(). The fix checks the supplied slot first, then the slot for the other address space, ensuring consistent write-tracking enforcement across all callers (Red Hat Advisory, GitHub Advisory).

Impact

Successful exploitation causes a host kernel panic (denial of service), crashing the KVM hypervisor and all virtual machines running on it. The impact is limited to availability — there is no evidence of confidentiality or integrity compromise. Because the crash affects the host kernel, all tenants sharing the same physical host in a multi-tenant virtualization environment would be disrupted simultaneously, making this particularly impactful in cloud or shared hosting scenarios (Feedly, Red Hat Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Feedly). Exploitation requires local access to a KVM host with the ability to create or control virtual machines, and SMM must be enabled in the guest configuration. The EPSS score is 0.0, reflecting very low probability of near-term exploitation. This CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (Red Hat Advisory).

Indicators of compromise

  • Logs: Kernel logs (dmesg, /var/log/kern.log) showing a kernel BUG or panic originating from pte_list_remove() or related KVM MMU functions (e.g., mmu_try_to_unsync_pages).
  • System Behavior: Unexpected KVM host crashes or reboots, particularly when SMM-enabled guests are running.
  • Process: Sudden termination of all guest VMs on a host without a graceful shutdown sequence, accompanied by a kernel oops or BUG trace in system logs.

Mitigation and workarounds

Apply the kernel patches backported to the following stable branches: 6.1.187, 6.6.156, 6.12.108, 6.18.49, 7.1.13, and 7.2 (mainline). The fix commits are available in the Linux stable kernel repository. As a workaround where patching is not immediately feasible, restrict unprivileged user access to KVM virtual machine creation, and consider disabling SMM in guest configurations if operationally acceptable. Monitor systems for unexpected kernel panics related to KVM page tracking (Red Hat Advisory, GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux: 6.1.187-1

Fixed

sid

linux: 7.1.13-1

Fixed

trixie

linux: 6.12.111-1

Fixed

Ubuntu

Unknown

bionic (esm-infra)

linux

Unknown

bionic (fips-updates)

linux-fips

Unknown

bionic (fips)

linux-fips

Unknown

devel

linux

Unknown

focal (esm-infra)

linux

Unknown

focal (fips-updates)

linux-fips

Unknown

focal (fips)

linux-fips

Unknown

jammy

linux

Unknown

RHEL / CentOS

Affected

OpenShift

openshift/ose-rhel-coreos-8

Affected

RHEL 8

kernel-rt.src

Affected

RHEL 9

kernel.src

Affected

RHEL 10

kernel.src

Affected

Source: This report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100075CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • linux-aws-6.17
NoYesSep 25, 2026
CVE-2026-98164MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-7.0
NoYesSep 29, 2026
CVE-2026-98161MEDIUM5.1
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoYesSep 25, 2026
CVE-2026-100074MEDIUM5.1
  • Linux Kernel logoLinux Kernel
  • linux-riscv-7.0
NoYesSep 25, 2026
CVE-2026-100073NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-raspi-5.4
NoYesSep 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management