CVE-2026-98249

Source
https://cve.org/CVERecord?id=CVE-2026-98249
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98249.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98249
Downstream
Published
2026-10-06T08:45:17Z
Modified
2026-10-08T02:52:55Z
Summary
arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
Details

In the Linux kernel, the following vulnerability has been resolved:

arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc

swsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub vectors with an hvc, but never passes the arguments. x0 is not set to HVC_SET_VECTORS and x1 is not set to the vector address, so the stub dispatch falls through and returns without writing vbar_el2. EL2 is left pointing at the trans_pgd copy of the vectors, a page that swsusp_free() releases right after resume.

Set the arguments up the same way __hyp_set_vectors() does.

Without this fix, Vladimir was able to trigger a hang when resuming from hibernation with CONFIG_PAGE_POISONING=y and page_poison=on.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98249.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
788bfdd97434982b6d575062581e8e72eea755af
Fixed
6646418d1032cac25110526161f60d255ed08397
Fixed
909e92423db7299e0206232051aa21fe129f65d0
Fixed
60a3c319f1127c4d247d4ed235c5d65376d5e745
Fixed
e80ea8118a073a30ebe7a31bd78938c2b1751acc
Fixed
d3f8f773312af69eaf4dda106d76d6d42e4362e5
Fixed
955d86e5f3b95b731991fdb84966c50b16314629

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98249.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98249.json"