Executive brief
A vulnerability in the Linux kernel's memory management system can cause a system crash (General Protection Fault) on certain AMD processors. This occurs when the system is specifically configured to disable a feature called Process-Context Identifiers (PCID) while using newer broadcast cache clearing mechanisms. An exploit would result in a complete system denial of service, requiring a reboot to recover.
Technical details
A vulnerability exists in the x86 memory management subsystem of the Linux kernel where the INVLPGB (broadcast TLB flushing) feature remains enabled even when PCID (Process-Context Identifiers) is disabled via the 'nopcid' boot parameter. When a memory management (mm) structure becomes active on more than three CPUs, the kernel assigns a global ASID and attempts a broadcast TLB flush. If this occurs while CR4.PCIDE is not set, the processor triggers a General Protection Fault (#GP). The fix involves making the X86_FEATURE_INVLPGB CPUID feature dependent on X86_FEATURE_PCID in the kernel's CPU dependency table.
Affected products
- Linux Linux 6.15 to 7.1
Timeline
- 2026-05-20: patched: Initial fix committed to mainline kernel
- 2026-07-24: disclosed: CVE published