The Linux kernel CVEs for 27 September to 3 October 2026 contain one record: CVE-2026-98164, a fix in the KVM x86 shadow MMU. It is not CNA-CRITICAL. The kernel CNA did not score it, and NVD scores it 5.5 MEDIUM (host denial of service). The fix is already in mainline. No record notes known exploitation, and we found no public exploit code. The action is to update to the fixed version for your branch if you run x86 KVM hosts. The 5.10 and 5.15 branches have no fix listed yet. Minimum safe versions: 6.1.187, 6.6.156, 6.12.108, 6.18.49, and any 7.2 or later release.
This is the smallest weekly edition so far. The previous three weeks had 443, 878 and 607 records. This week the kernel CNA published one. The next CVE IDs in the kernel sequence are reserved but not yet published, so a larger batch may appear next week. We publish every week, so this edition reports the one record. It matters only to products that run x86 virtual machines on KVM. Phones, most automotive units and ARM-based embedded boards do not run this code.
The one action: update to the fixed version for your branch
Find your branch in the table. If your kernel version is lower than the value in the second column, and the product runs KVM guests on x86, plan the update.
| Stable branch | Update to at least | Notes |
|---|---|---|
| 5.10 | No fix listed | Longterm. The bug exists since 4.2, but the record names no 5.10 fix. Projected end of life: December 2026. |
| 5.15 | No fix listed | Longterm. The record names no 5.15 fix. Projected end of life: December 2026. |
| 6.1 | 6.1.187 | Longterm. The newest release is 6.1.189. |
| 6.6 | 6.6.156 | Longterm. The newest release is 6.6.158. |
| 6.12 | 6.12.108 | Longterm. The newest release is 6.12.112. |
| 6.18 | 6.18.49 | Longterm. The newest release is 6.18.55. |
| 7.1 | End of life | 7.1.13 has the fix and was the final release. Move to 7.2. |
| 7.2 | Any 7.2 release | Current stable. The mainline fix is in 7.2, so every 7.2.y release has it. The newest release is 7.2.9. |
| mainline | 7.2 or later | 7.3-rc5 has the fix. |
Each value is the fixed version named in the record. Each one was checked against kernel.org on 3 October 2026, and each is at or below the newest release on its branch. Branches that are not listed were not affected by this week’s record. If you already applied last week’s table, you already have this fix on 6.1, 6.6, 6.12, 6.18 and 7.2.
Mobile and automotive
No record this week applies to this vertical. The bug is in arch/x86/kvm. Phones and most automotive head units and telematics units use ARM processors, and ARM KVM does not use this code. An x86 in-vehicle computer that runs guest virtual machines on KVM is the exception. It should follow the Cloud and datacenter section.
Embedded and IoT
Most embedded and IoT devices are not affected. The bug applies only to x86 devices that run guest virtual machines on KVM, for example an x86 edge gateway or an industrial PC that hosts virtual machines. Those devices should follow the Cloud and datacenter section below.
Cloud and datacenter
This vertical has the one record of the week. It applies to x86 hosts that run KVM guests.
CVE-2026-98164: KVM x86 shadow MMU write tracking
KVM tracks writes to some guest pages. The function kvm_gfn_is_write_tracked() checked only the memory slot it was given. Write tracking is kept per address space, but shadow pages are shared across address spaces. When a guest uses SMM (System Management Mode), a page can be write-tracked in one address space and look untracked in the other. KVM can then mark an upper-level shadow page as unsync and later hit the BUG in pte_list_remove(). This crashes the host kernel. NVD scores it 5.5 MEDIUM with a local vector and an availability-only impact. On a shared host, one guest can crash the host, which stops every guest on it, so plan the update for shared x86 KVM hosts first. The code path is the shadow MMU. KVM uses it when the host runs without two-dimensional paging (EPT on Intel, NPT on AMD), and also for nested guests. The gate is CONFIG_KVM with CONFIG_KVM_INTEL or CONFIG_KVM_AMD. On 6.2 and later, guest SMM support is built only when CONFIG_KVM_SMM is set. The bug exists since 4.2. Fixed in 6.1.187, 6.6.156, 6.12.108, 6.18.49 and 7.1.13. The mainline fix is in 7.2. The record lists no fix for 5.10 and 5.15. See CVE-2026-98164.
Medical devices
No record this week applies to medical devices, unless a device or its back-end server hosts x86 KVM guest virtual machines. In that case, follow the Cloud and datacenter section for CVE-2026-98164. Medical-device patching is gated by validation and regulatory revalidation (US FDA postmarket cybersecurity guidance, EU MDR, IEC 62304), so the action is to plan the stable update through the manufacturer’s change-control process.
How to check if Linux kernel CVEs apply to you
Ask three questions for each record.
- Version. Is your kernel version lower than the table value for your branch? If yes, the fix is not in your kernel.
- Configuration. Is the affected code built? Search the running configuration for the symbol named in the record section.
- Reachability. Who can reach the code? Remote or over-the-air paths come first. Local unprivileged paths come next. Guest-to-host paths on shared hosts come after that. Paths that need root or a special configuration come last. This week’s record is a guest-to-host path.
raghu@techveda.org:~$ zcat /proc/config.gz | grep -E 'CONFIG_KVM=|CONFIG_KVM_INTEL=|CONFIG_KVM_AMD=|CONFIG_KVM_SMM='
CONFIG_KVM=m
CONFIG_KVM_INTEL=m
CONFIG_KVM_AMD=m
CONFIG_KVM_SMM=y
raghu@techveda.org:~$ cat /sys/module/kvm_intel/parameters/ept
YIf /proc/config.gz does not exist, check the configuration file in /boot or the build tree for the image. On AMD hosts, read /sys/module/kvm_amd/parameters/npt instead of the ept parameter. Two-dimensional paging being on does not remove the risk, because KVM uses the shadow MMU for nested guests.
Key takeaways
- One Linux kernel CVE was published between 27 September and 3 October 2026:
CVE-2026-98164. - No record is CNA-CRITICAL. NVD scores this one 5.5 MEDIUM, a host denial of service.
- It applies only to x86 hosts that run KVM guests. ARM devices are not affected.
- Minimum safe versions: 6.1.187, 6.6.156, 6.12.108, 6.18.49, and any 7.2 or later release.
- The record lists no fix for 5.10 and 5.15.
- No record notes known exploitation.
Frequently asked questions
Why is there only one Linux kernel CVE this week?
The kernel CNA published one record in this window. The previous three weeks had between 443 and 878. The next IDs in the kernel sequence are reserved but not yet published, so the next edition may be larger.
Is my embedded board affected by CVE-2026-98164?
Only if it is an x86 system that runs guest virtual machines on KVM. The bug is in x86 KVM code. ARM boards and devices that do not host virtual machines do not run it.
Is there a known exploit for CVE-2026-98164?
The record does not note known exploitation, and we found no public exploit code at the time of writing. The fix is already in mainline.
I applied last week’s minimum safe versions. Do I need to do anything?
No, if you are on 6.1, 6.6, 6.12, 6.18 or 7.2. Last week’s versions are all higher than this week’s fixed versions. On 5.10 and 5.15 no fix is listed yet.
Why does the table show no fix for 5.10 and 5.15?
The record says the bug exists since 4.2, but it names fixed versions only for 6.1 and later. Until a fix is listed, an x86 KVM host on 5.10 or 5.15 stays exposed. Plan the move to a newer longterm branch.




