Sceawere
Vulnerability Detail
CVE-2026-19574UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ARM64 ASID Collision Memory Isolation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7
- Creation Date
- 3h ago
- Vendor
- zephyrproject
- Product
- zephyr
- Attack Type
- auth
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The ARM64 MMU back-end allocated address space identifiers (ASIDs) for memory domains with a bare round-robin counter in arch_mem_domain_init() (arch/arm64/core/mmu.c). VM_ASID_BITS is 8, so only 255 ASIDs exist; once the counter wrapped, arch_mem_domain_init() could hand an ASID to a new domain while a still-live domain held the same one. Domain-private mappings are installed non-global (MT_NG), so the ASID is the only tag separating one domain's cached translations from another's in the TLB. The context-switch path in z_arm64_swap_ptables() only flushes the TLB when the outgoing and incoming domains carry the same ASID, which does not cover a duplicate reached through a third domain: for domains A and C sharing an ASID and an unrelated domain B, the schedule A -> B -> C never takes the flush branch, so the ASID-tagged entries A populated remain resident while C runs. Under SMP two live domains sharing an ASID can additionally be resident on two CPUs at once, which the architecture does not allow for distinct translation-table sets. Triggering the wrap requires a CONFIG_USERSPACE application on ARM64 that creates more than 255 memory domains over its lifetime; k_mem_domain_init() and k_mem_domain_deinit() are supervisor-only APIs and are not exposed as syscalls, so an unprivileged thread cannot drive the counter directly. Once two live domains alias, however, a user-mode thread in one domain can read and write memory belonging to the other domain's partitions and thread stacks with that domain's permissions, defeating the memory-domain isolation boundary. The fix scans the live domain_list before assigning an ASID, advances the round-robin counter past ASIDs already in use, and returns -ENOMEM when all are taken, so domain creation fails closed instead of silently aliasing.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.0",
"pubDate": "2026-10-09T08:16:54.940Z",
"pubdate": "2026-10-09T08:16:54.940Z",
"executiveSummary": "A critical memory isolation vulnerability exists in the ARM64 MMU back-end, specifically within arch/arm64/core/mmu.c, where insufficient ASID management leads to domain aliasing.\nThe vulnerability occurs because the kernel employs a simple round-robin counter to assign 8-bit Address Space Identifiers (ASIDs) to memory domains without checking for existing assignments.\nWhen the counter wraps after 255 allocations, a newly created domain can be assigned an ASID currently in use by an active domain.\nBecause the TLB uses the ASID to differentiate cached translations for non-global (MT_NG) mappings, this collision allows one memory domain to access the memory space, stack, and partitions of another.\nWhile unprivileged threads cannot directly trigger the counter wrap, any system that creates more than 255 memory domains over its lifecycle is susceptible.\nAn attacker who successfully triggers an ASID collision can achieve unauthorized cross-domain memory access, effectively bypassing the memory domain isolation boundary enforced by the kernel.\nThe risk is exacerbated in SMP environments where two colliding domains may be resident on different CPUs simultaneously, violating architectural requirements for distinct translation-table sets.",
"technicalDetails": "The root cause of the vulnerability lies in the arch_mem_domain_init() function in arch/arm64/core/mmu.c. The implementation uses an 8-bit counter (VM_ASID_BITS = 8) to issue ASIDs in a bare round-robin fashion without validating whether the candidate ASID is currently in use by another active memory domain.\nIn the ARM64 architecture, ASIDs act as a primary tag for TLB entries related to non-global (MT_NG) memory mappings. When the kernel performs a context switch via z_arm64_swap_ptables(), it only flushes the TLB if the incoming and outgoing domains share an ASID. This logic is flawed; if Domain A and Domain C both share the same ASID, the transition path A -> B -> C fails to trigger a flush because the intermediate context B does not share the ASID. Consequently, TLB entries belonging to Domain A remain resident and accessible while Domain C is executing.\nExploitation requires the creation of 255 memory domains. While k_mem_domain_init() and k_mem_domain_deinit() are supervisor-only, an attacker can leverage any legitimate system functionality that creates memory domains to induce a wrap-around of the ASID counter. Once a collision occurs, the hardware MMU cannot distinguish between the translation tables of the two domains.\nThe attack flow follows these steps: 1. The attacker induces the exhaustion of the 255 available ASIDs through successive domain creation cycles. 2. A target domain and a victim domain are assigned the same ASID by the round-robin logic. 3. The attacker thread, residing within the target domain, performs memory operations that hit the incorrectly tagged TLB entries of the victim domain. 4. The MMU permits access to the victim's memory, including partitions and thread stacks, using the victim's permissions. In SMP systems, this collision can exist simultaneously on multiple physical cores, leading to potential data corruption or unauthorized information disclosure across the entire domain boundary."
}