Answer in brief
CVE-2026-98249 records a Unknown severity vulnerability in arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=788bfdd97434982b6d575062581e8e72eea755af <6646418d1032cac25110526161f60d255ed08397 || >=788bfdd97434982b6d575062581e8e72eea755af <909e92423db7299e0206232051aa21fe129f65d0 || >=788bfdd97434982b6d575062581e8e72eea755af <60a3c319f1127c4d247d4ed235c5d65376d5e745 || >=788bfdd97434982b6d575062581e8e72eea755af <e80ea8118a073a30ebe7a31bd78938c2b1751acc || >=788bfdd97434982b6d575062581e8e72eea755af <d3f8f773312af69eaf4dda106d76d6d42e4362e5 || >=788bfdd97434982b6d575062581e8e72eea755af <955d86e5f3b95b731991fdb84966c50b16314629 | 6646418d1032cac25110526161f60d255ed08397, 909e92423db7299e0206232051aa21fe129f65d0, 60a3c319f1127c4d247d4ed235c5d65376d5e745, e80ea8118a073a30ebe7a31bd78938c2b1751acc, d3f8f773312af69eaf4dda106d76d6d42e4362e5, 955d86e5f3b95b731991fdb84966c50b16314629 |
| Linux/Linuxgeneric | 5.16 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: arm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc swsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub vectors with an hvc, but never passes the arguments. x0 is not set to HVC_SET_VECTORS and x1 is not set to the vector address, so the stub dispatch falls through and returns without writing vbar_el2. EL2 is left pointing at the trans_pgd copy of the vectors, a page that swsusp_free() releases right after resume. Set the arguments up the same way __hyp_set_vectors() does. Without this fix, Vladimir was able to trigger a hang when resuming from hibernation with CONFIG_PAGE_POISONING=y and page_poison=on.
Quoted source text, attributed separately from HOL analysis.