Junglewise Threat Intelligence

CVE-2026-64229: Linux Kernel general protection fault in x86 broadcast TLB flushing

CVE-2026-64229 · Severity: info · CVSS 4.7 · Published 2026-07-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory management system can cause a system crash (General Protection Fault) on certain AMD processors. This occurs when the system is specifically configured to disable a feature called Process-Context Identifiers (PCID) while using newer broadcast cache clearing mechanisms. An exploit would result in a complete system denial of service, requiring a reboot to recover.

Technical details

A vulnerability exists in the x86 memory management subsystem of the Linux kernel where the INVLPGB (broadcast TLB flushing) feature remains enabled even when PCID (Process-Context Identifiers) is disabled via the 'nopcid' boot parameter. When a memory management (mm) structure becomes active on more than three CPUs, the kernel assigns a global ASID and attempts a broadcast TLB flush. If this occurs while CR4.PCIDE is not set, the processor triggers a General Protection Fault (#GP). The fix involves making the X86_FEATURE_INVLPGB CPUID feature dependent on X86_FEATURE_PCID in the kernel's CPU dependency table.

Affected products

  • Linux Linux 6.15 to 7.1

Timeline

  • 2026-05-20: patched: Initial fix committed to mainline kernel
  • 2026-07-24: disclosed: CVE published

References