{"id":"CVE-2026-98249","title":"In the Linux kernel, the following vulnerability has been resolved:\n\narm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc\n\nswsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub\nvectors with an hvc, but never passe…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\narm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc\n\nswsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub\nvectors with an hvc, but never passe…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 788bfdd97434982b6d575062581e8e72eea755af < 6646418d1032cac25110526161f60d255ed08397","Linux >= 788bfdd97434982b6d575062581e8e72eea755af < 909e92423db7299e0206232051aa21fe129f65d0","Linux >= 788bfdd97434982b6d575062581e8e72eea755af < 60a3c319f1127c4d247d4ed235c5d65376d5e745","Linux >= 788bfdd97434982b6d575062581e8e72eea755af < e80ea8118a073a30ebe7a31bd78938c2b1751acc","Linux >= 788bfdd97434982b6d575062581e8e72eea755af < d3f8f773312af69eaf4dda106d76d6d42e4362e5","Linux >= 788bfdd97434982b6d575062581e8e72eea755af < 955d86e5f3b95b731991fdb84966c50b16314629","Linux 5.16"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:13.290","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98249","references":[{"url":"https://git.kernel.org/stable/c/60a3c319f1127c4d247d4ed235c5d65376d5e745","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6646418d1032cac25110526161f60d255ed08397","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/909e92423db7299e0206232051aa21fe129f65d0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/955d86e5f3b95b731991fdb84966c50b16314629","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3f8f773312af69eaf4dda106d76d6d42e4362e5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e80ea8118a073a30ebe7a31bd78938c2b1751acc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.431Z","slug":"CVE-2026-98249","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\narm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc\n\nswsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub\nvectors with an hvc, but never passes the arguments. x0 is not set to\nHVC_SET_VECTORS and x1 is not set to the vector address, so the stub\ndispatch falls through and returns without writing vbar_el2. EL2 is\nleft pointing at the trans_pgd copy of the vectors, a page that\nswsusp_free() releases right after resume.\n\nSet the arguments up the same way __hyp_set_vectors() does.\n\nWithout this fix, Vladimir was able to trigger a hang when resuming from\nhibernation with CONFIG_PAGE_POISONING=y and page_poison=on.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}