Database/Control plane, storage & DevOps
Linux x86/mm - broadcast TLB flush with PCID disabled: Booting with nopcid clears the PCID feature but broadcast TLB
Impact
Booting with nopcid clears the PCID feature but broadcast TLB flushing stayed enabled, leaving TLB invalidation in an inconsistent configuration. Stale TLB entries are a memory-isolation problem: a translation that should have been invalidated but was not means one address space can still reach a mapping that was revoked.
Who can reach it
Local, on hosts booted with nopcid. Not attacker-selected unless the attacker controls boot parameters - but plenty of fleets set nopcid for debugging or for old mitigation workarounds and forget it.
What to do
Fixed in the Linux kernel. Distro kernel update plus reboot. Also audit your boot parameters: nopcid is a performance and now correctness liability that is often left in place long after the reason for it is gone.
References
Related entries
- Linux crypto/ccp - SNP initialization on ioctl(SNP_COMMIT): The ccp driver initialised SNP from the SNP_COMMIT ioctlCVE-2026-64309 · Linux crypto/ccp - SNP initialization on ioctl(SNP_COMMIT)Unscored
- Linux iommu/amd - IRQ-unsafe locking in guest domain allocation: An IRQ-unsafe lock taken during AMD IOMMU guest domainCVE-2026-68347 · Linux iommu/amd - IRQ-unsafe locking in guest domain allocationUnscored
- Linux perf/x86/amd/core - Branch Sampling enabled from the SVM reload path: Branch Sampling and Last Branch RecordCVE-2026-72325 · Linux perf/x86/amd/core - Branch Sampling enabled from the SVM reload pathUnscored
- Linux kernel NFSv4 client: a delayed FREE_STATEID can use a freed nfs_serverCVE-2026-74730 · Linux kernel NFSv4 client (nfs_server lifetime across FREE_STATEID)Unscored
- NVMe/TCP host: a short read is reported to userspace as a complete readCVE-2026-89480 · Linux kernel nvme-tcp host (short-read completion accounting)Unscored
- NVMe/TCP host: a malicious target can read host kernel memory by sending R2T for a READCVE-2026-89481 · Linux kernel nvme-tcp host (R2T direction check)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.