Database/Control plane, storage & DevOps
Linux x86/CPU/AMD - INVLPGB on Zen 2 (Cyan Skillfish): Using broadcast TLB invalidation (INVLPGB) on affected Zen 2
CVSS 5.5CVE-2025-38518Control plane, storage & DevOpscurated
Impact
Using broadcast TLB invalidation (INVLPGB) on affected Zen 2 parts oopses the system. TLB invalidation is core memory-management machinery, so a defect here is both a stability problem and, in principle, a correctness problem for the mappings that separate address spaces.
Who can reach it
Local, triggered by normal kernel memory management on affected silicon rather than by an attacker.
What to do
Fixed in the Linux kernel by disabling INVLPGB on affected parts. Distro kernel update plus reboot.
References
Related entries
- SPDK (Storage Performance Development Kit) 25.05 - NVMe-oF target, lib/nvmf: A buffer overflow in the NVMe-oF targetCVE-2025-57275 · SPDK (Storage Performance Development Kit) 25.05 - NVMe-oF target, lib/nvmfMedium
- HashiCorp go-slug: Unicode normalization mismatch lets excluded files slip past .terraformignore into the uploadCVE-2026-14978 · HashiCorp go-slug (.terraformignore path matching, Unicode normalization)Medium
- IBM Storage Scale management GUI (deploy and upgrade logging): The Storage Scale admin password is written in the clearCVE-2026-19483 · IBM Storage Scale management GUI (deploy and upgrade logging)Medium
- Linux kernel CephFS client: invalid kfree() when listing .snap directories oopses the nodeCVE-2026-23201 · Linux kernel CephFS client (parse_longname snapshot handling)Medium
- Linux perf/x86 - event pointer setup ordering in x86_pmu_enable(): A NULL pointer dereference in the x86 PMU enableCVE-2026-23435 · Linux perf/x86 - event pointer setup ordering in x86_pmu_enable()Medium
- GitLab EE: project Maintainer can open a terminal on a protected environment they are not authorized forCVE-2026-3035 · GitLab EE (protected environment terminal authorization)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.