CVE-2026-90212

Source
https://cve.org/CVERecord?id=CVE-2026-90212
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90212.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90212
Downstream
Published
2026-09-17T16:07:26Z
Modified
2026-09-19T03:47:25Z
Summary
arm64/efi: Avoid voluntary preemption with efi_mm installed
Details

In the Linux kernel, the following vulnerability has been resolved:

arm64/efi: Avoid voluntary preemption with efi_mm installed

Gus reports a bad kernel memory access when using software PAN (CONFIG_ARM64_SW_TTBR0_PAN=y) on a machine with support for EFI runtime services:

Unable to handle kernel access to user memory outside uaccess routines at virtual address 00000000f322ff30 Mem abort info: ESR = 0x0000000096000004 FSC = 0x04: level 0 translation fault Internal error: Oops: 0000000096000004 [#1] SMP Workqueue: efi_rts_wq efi_call_rts pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : efi_call_rts+0xd8/0x288 Call trace: efi_call_rts+0xd8/0x288 (P) process_one_work+0x178/0x4f8 worker_thread+0x194/0x328

This is because the fpsimd context management code called from __efi_fpsimd_begin() can preempt voluntarily, returning later to the EFI code with an incorrect value for TTBR0_EL1 thanks to the deferred mm switching used by the software PAN implementation.

Since EFI runtime services cannot preempt voluntarily and because the fpsimd switching code does not rely on the TTBR0_EL1 mappings, simply reorder the fpsimd switch so that it occurs before we change the page-table.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90212.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a5baf582f4c026c25a206ac121bceade926aec74
Fixed
829539c4a650544cb8e5e8690f2c2d0aa2c0e298
Fixed
e98a9d0146372b046d863164025a66ab4488b972

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90212.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90212.json"