Sceawere

Vulnerability Detail

CVE-2026-19574UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ARM64 ASID Collision Memory Isolation

Vulnerability Metadata

Severity
High
Score / CVSS
7
Creation Date
3h ago
Vendor
zephyrproject
Product
zephyr
Attack Type
auth
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

The ARM64 MMU back-end allocated address space identifiers (ASIDs) for memory domains with a bare round-robin counter in arch_mem_domain_init() (arch/arm64/core/mmu.c). VM_ASID_BITS is 8, so only 255 ASIDs exist; once the counter wrapped, arch_mem_domain_init() could hand an ASID to a new domain while a still-live domain held the same one. Domain-private mappings are installed non-global (MT_NG), so the ASID is the only tag separating one domain's cached translations from another's in the TLB. The context-switch path in z_arm64_swap_ptables() only flushes the TLB when the outgoing and incoming domains carry the same ASID, which does not cover a duplicate reached through a third domain: for domains A and C sharing an ASID and an unrelated domain B, the schedule A -> B -> C never takes the flush branch, so the ASID-tagged entries A populated remain resident while C runs. Under SMP two live domains sharing an ASID can additionally be resident on two CPUs at once, which the architecture does not allow for distinct translation-table sets. Triggering the wrap requires a CONFIG_USERSPACE application on ARM64 that creates more than 255 memory domains over its lifetime; k_mem_domain_init() and k_mem_domain_deinit() are supervisor-only APIs and are not exposed as syscalls, so an unprivileged thread cannot drive the counter directly. Once two live domains alias, however, a user-mode thread in one domain can read and write memory belonging to the other domain's partitions and thread stacks with that domain's permissions, defeating the memory-domain isolation boundary. The fix scans the live domain_list before assigning an ASID, advances the round-robin counter past ASIDs already in use, and returns -ENOMEM when all are taken, so domain creation fails closed instead of silently aliasing.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.0",
  "pubDate": "2026-10-09T08:16:54.940Z",
  "pubdate": "2026-10-09T08:16:54.940Z",
  "executiveSummary": "A critical memory isolation vulnerability exists in the ARM64 MMU back-end, specifically within arch/arm64/core/mmu.c, where insufficient ASID management leads to domain aliasing.\nThe vulnerability occurs because the kernel employs a simple round-robin counter to assign 8-bit Address Space Identifiers (ASIDs) to memory domains without checking for existing assignments.\nWhen the counter wraps after 255 allocations, a newly created domain can be assigned an ASID currently in use by an active domain.\nBecause the TLB uses the ASID to differentiate cached translations for non-global (MT_NG) mappings, this collision allows one memory domain to access the memory space, stack, and partitions of another.\nWhile unprivileged threads cannot directly trigger the counter wrap, any system that creates more than 255 memory domains over its lifecycle is susceptible.\nAn attacker who successfully triggers an ASID collision can achieve unauthorized cross-domain memory access, effectively bypassing the memory domain isolation boundary enforced by the kernel.\nThe risk is exacerbated in SMP environments where two colliding domains may be resident on different CPUs simultaneously, violating architectural requirements for distinct translation-table sets.",
  "technicalDetails": "The root cause of the vulnerability lies in the arch_mem_domain_init() function in arch/arm64/core/mmu.c. The implementation uses an 8-bit counter (VM_ASID_BITS = 8) to issue ASIDs in a bare round-robin fashion without validating whether the candidate ASID is currently in use by another active memory domain.\nIn the ARM64 architecture, ASIDs act as a primary tag for TLB entries related to non-global (MT_NG) memory mappings. When the kernel performs a context switch via z_arm64_swap_ptables(), it only flushes the TLB if the incoming and outgoing domains share an ASID. This logic is flawed; if Domain A and Domain C both share the same ASID, the transition path A -> B -> C fails to trigger a flush because the intermediate context B does not share the ASID. Consequently, TLB entries belonging to Domain A remain resident and accessible while Domain C is executing.\nExploitation requires the creation of 255 memory domains. While k_mem_domain_init() and k_mem_domain_deinit() are supervisor-only, an attacker can leverage any legitimate system functionality that creates memory domains to induce a wrap-around of the ASID counter. Once a collision occurs, the hardware MMU cannot distinguish between the translation tables of the two domains.\nThe attack flow follows these steps: 1. The attacker induces the exhaustion of the 255 available ASIDs through successive domain creation cycles. 2. A target domain and a victim domain are assigned the same ASID by the round-robin logic. 3. The attacker thread, residing within the target domain, performs memory operations that hit the incorrectly tagged TLB entries of the victim domain. 4. The MMU permits access to the victim's memory, including partitions and thread stacks, using the victim's permissions. In SMP systems, this collision can exist simultaneously on multiple physical cores, leading to potential data corruption or unauthorized information disclosure across the entire domain boundary."
}
CVE-2026-19574: ARM64 ASID Collision Memory Isolation (HIGH Severity, CVSS: 7.0) | Sceawere