CVE-2026-63875 Affecting kernel-tools-libs-devel package, versions <0:4.18.0-553.169.1.el8_10


Severity

Recommended
high

Based on AlmaLinux security rating.

Threat Intelligence

EPSS
0.18% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ALMALINUX8-KERNELTOOLSLIBSDEVEL-20250329
  • published29 Sept 2026
  • disclosed28 Sept 2026

Introduced: 28 Sep 2026

NewCVE-2026-63875  (opens in a new tab)

How to fix?

Upgrade AlmaLinux:8 kernel-tools-libs-devel to version 0:4.18.0-553.169.1.el8_10 or higher.
This issue was patched in ALSA-2026:72468.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kernel-tools-libs-devel package and not the kernel-tools-libs-devel package as distributed by AlmaLinux. See How to fix? for AlmaLinux:8 relevant fixed versions and status.

In the Linux kernel, the following vulnerability has been resolved:

arm64: tlb: Flush walk cache when unsharing PMD tables

When huge_pmd_unshare() is called to unshare a PMD table, the tlb_unshare_pmd_ptdesc() function sets tlb->unshared_tables=true but the aarch64 tlb_flush() only checked tlb->freed_tables to determine whether to use TLBF_NONE (vae1is, invalidates walk cache) or TLBF_NOWALKCACHE (vale1is, leaf-only).

This caused the stale PMD page table entry to remain in the walk cache after unshare, potentially leading to incorrect page table walks.

Fix by including unshared_tables in the check, so that when unsharing tables, TLBF_NONE is used and the walk cache is properly invalidated.

Here is the detailed distinction between vae1is and vale1is:

Instruction Combination Actual Invalidation Scope
VAE1IS + TTL=0 All entries at all levels (full invalidation)
VAE1IS + TTL=2 (L2) Non-leaf at Level 0/1 + leaf at Level 2
VALE1IS + TTL=0 Leaf entries at all levels (non-leaf not cleared)
VALE1IS + TTL=2 (L2) Leaf entry at Level 2 only

CVSS Base Scores

version 3.1