CVE-2026-98249 PUBLISHED

arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc

swsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub vectors with an hvc, but never passes the arguments. x0 is not set to HVC_SET_VECTORS and x1 is not set to the vector address, so the stub dispatch falls through and returns without writing vbar_el2. EL2 is left pointing at the trans_pgd copy of the vectors, a page that swsusp_free() releases right after resume.

Set the arguments up the same way __hyp_set_vectors() does.

Without this fix, Vladimir was able to trigger a hang when resuming from hibernation with CONFIG_PAGE_POISONING=y and page_poison=on.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 788bfdd97434982b6d575062581e8e72eea755af to 6646418d1032cac25110526161f60d255ed08397 (excl.)
  • affected from 788bfdd97434982b6d575062581e8e72eea755af to 909e92423db7299e0206232051aa21fe129f65d0 (excl.)
  • affected from 788bfdd97434982b6d575062581e8e72eea755af to 60a3c319f1127c4d247d4ed235c5d65376d5e745 (excl.)
  • affected from 788bfdd97434982b6d575062581e8e72eea755af to e80ea8118a073a30ebe7a31bd78938c2b1751acc (excl.)
  • affected from 788bfdd97434982b6d575062581e8e72eea755af to d3f8f773312af69eaf4dda106d76d6d42e4362e5 (excl.)
  • affected from 788bfdd97434982b6d575062581e8e72eea755af to 955d86e5f3b95b731991fdb84966c50b16314629 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.16 is affected
  • unaffected from 0 to 5.16 (excl.)
  • unaffected from 6.1.189 to 6.1.* (incl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References