CVE-2026-98249
Received Received - Intake

Kernel Hibernation Vector Restoration Flaw in Linux

Vulnerability report for CVE-2026-98249, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc swsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub vectors with an hvc, but never passes the arguments. x0 is not set to HVC_SET_VECTORS and x1 is not set to the vector address, so the stub dispatch falls through and returns without writing vbar_el2. EL2 is left pointing at the trans_pgd copy of the vectors, a page that swsusp_free() releases right after resume. Set the arguments up the same way __hyp_set_vectors() does. Without this fix, Vladimir was able to trigger a hang when resuming from hibernation with CONFIG_PAGE_POISONING=y and page_poison=on.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
Linux Linux 788bfdd97434982b6d575062581e8e72eea755af
Linux Linux 788bfdd97434982b6d575062581e8e72eea755af
Linux Linux 788bfdd97434982b6d575062581e8e72eea755af
Linux Linux 788bfdd97434982b6d575062581e8e72eea755af
Linux Linux 788bfdd97434982b6d575062581e8e72eea755af
Linux Linux 788bfdd97434982b6d575062581e8e72eea755af
Linux Linux 5.16

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the hibernation process for arm64 systems. When resuming from hibernation, the kernel fails to properly set arguments for the HVC_SET_VECTORS call, leaving the EL2 exception vector address unupdated. This can cause the system to hang during resume if specific configurations like CONFIG_PAGE_POISONING are enabled.

Detection Guidance

This vulnerability is specific to the Linux kernel's arm64 hibernation functionality and cannot be detected via standard network or system commands. It requires kernel-level inspection to identify if the hibernation resume process fails to set hyp stub vectors correctly.

Impact Analysis

If you use a Linux system with arm64 architecture and hibernation enabled, this vulnerability could cause your system to hang or crash when resuming from hibernation. This may lead to data loss or require a forced reboot, disrupting normal operations.

Mitigation Strategies

Apply the latest kernel update from your Linux distribution to ensure the fix for CVE-2026-98249 is included. If hibernation is not required, disable it as a temporary workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98249. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart