CVE-2026-98249
Received
Received - Intake
Kernel Hibernation Vector Restoration Flaw in Linux
Vulnerability report for CVE-2026-98249, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc
swsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub
vectors with an hvc, but never passes the arguments. x0 is not set to
HVC_SET_VECTORS and x1 is not set to the vector address, so the stub
dispatch falls through and returns without writing vbar_el2. EL2 is
left pointing at the trans_pgd copy of the vectors, a page that
swsusp_free() releases right after resume.
Set the arguments up the same way __hyp_set_vectors() does.
Without this fix, Vladimir was able to trigger a hang when resuming from
hibernation with CONFIG_PAGE_POISONING=y and page_poison=on.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 788bfdd97434982b6d575062581e8e72eea755af |
| Linux | Linux | 788bfdd97434982b6d575062581e8e72eea755af |
| Linux | Linux | 788bfdd97434982b6d575062581e8e72eea755af |
| Linux | Linux | 788bfdd97434982b6d575062581e8e72eea755af |
| Linux | Linux | 788bfdd97434982b6d575062581e8e72eea755af |
| Linux | Linux | 788bfdd97434982b6d575062581e8e72eea755af |
| Linux | Linux | 5.16 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |