CVE-2026-98164·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are shared across all address spaces. With SMM, a GFN can therefore be write-tracked in one address space and appear untracked through the other. Check the supplied slot first, then the slot for the other address space. This ensures all callers honor write tracking regardless of the active address space. In particular, it prevents mmu_try_to_unsync_pages() from marking an upper-level shadow page unsync and eventually triggering the BUG in pte_list_remove(). [invert direction of the conditional. - Paolo]
- Severity
- medium
- Software
- Kernel
- Fixed in
- 7.1.13
- Published
- 2026-09-29
Affected versions
From: 6.19
Until: 7.1.13
Fixed in: 7.1.13
How to fix this CVE
Update your Linux kernel to version 7.1.13 or later to resolve a memory management unit (MMU) tracking inconsistency that could cause system instability. This patch ensures write-tracking metadata is properly checked across all KVM address spaces, preventing unsynchronized shadow page table corruption. Apply the update through your distribution's package manager at your earliest convenience.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Run `uname -r` to display your current kernel version and compare against the affected range 6.19–7.1.12.
- Check if KVM virtualization is enabled with `kvm-ok` (Ubuntu/Debian) or `grep -c 'vmx\|svm' /proc/cpuinfo` to confirm the vulnerable code path is present.
- Search kernel logs for KVM-related errors with `dmesg | grep -i 'kvm\|mmu\|pte_list' | tail -20` to identify any shadow page table corruption events.
- After patching, verify the new kernel is running with `uname -r` and ensure it displays 7.1.13 or later.
FAQ
What is CVE-2026-98164?
This is a Linux kernel vulnerability in KVM's memory management unit (MMU) that fails to consistently check write-tracking metadata across different address spaces used in System Management Mode (SMM). This inconsistency can allow shadow page tables to become unsynchronized and trigger kernel crashes.
Is CVE-2026-98164 being actively exploited?
No, there is no evidence of active exploitation in the wild, and no public exploits are available for this vulnerability.
What versions of Kernel are affected by CVE-2026-98164?
Linux kernel versions 6.19 through 7.1.12 are affected. Version 7.1.13 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-98164?
Run `uname -r` and compare the output against 6.19–7.1.12. If your kernel falls within this range, your system is vulnerable and requires an update.
Does Defensia detect CVE-2026-98164?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2026-98164 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/09aa68552d2542cc6c23edd1568ac265dc5d886f
- https://git.kernel.org/stable/c/0f38453cdb2e17566ccb7c0f3dabd5bd21caca26
- https://git.kernel.org/stable/c/429b6f43b4d8c98988fdca99e02dc156134e3d77
- https://git.kernel.org/stable/c/c0a9bd5fca0b5f2dea32b0fc31350e71e8648112
- https://git.kernel.org/stable/c/d8636c8f9f95d0fd1e2f6f1cad0d5757aa6f212a
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-98164. Free for 1 server.
Get started free