CVE-2026-98249

high

Description

In the Linux kernel, the following vulnerability has been resolved: arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc swsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub vectors with an hvc, but never passes the arguments. x0 is not set to HVC_SET_VECTORS and x1 is not set to the vector address, so the stub dispatch falls through and returns without writing vbar_el2. EL2 is left pointing at the trans_pgd copy of the vectors, a page that swsusp_free() releases right after resume. Set the arguments up the same way __hyp_set_vectors() does. Without this fix, Vladimir was able to trigger a hang when resuming from hibernation with CONFIG_PAGE_POISONING=y and page_poison=on.

References

https://git.kernel.org/stable/c/e80ea8118a073a30ebe7a31bd78938c2b1751acc

https://git.kernel.org/stable/c/d3f8f773312af69eaf4dda106d76d6d42e4362e5

https://git.kernel.org/stable/c/955d86e5f3b95b731991fdb84966c50b16314629

https://git.kernel.org/stable/c/909e92423db7299e0206232051aa21fe129f65d0

https://git.kernel.org/stable/c/6646418d1032cac25110526161f60d255ed08397

https://git.kernel.org/stable/c/60a3c319f1127c4d247d4ed235c5d65376d5e745

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93177

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Severity: High

EPSS

EPSS: 0.0018