CVE-2026-19574 Zephyr ARM64 MMU ASID 分配漏洞
影响可导致 TLB 残留错误翻译,造成内存隔离失效或越权访问
Zephyr 的 ARM64 MMU 后端在 arch_mem_domain_init() 中使用简单的轮询计数器分配 ASID,而 VM_ASID_BITS 为 8,仅 255 个可用 ASID。计数器回绕后,新内存域可能获得仍被存活域占用的 ASID,破坏域间 TLB 隔离。
影响范围
受影响组件为 Zephyr 的 ARM64 MMU 后端(arch/arm64/core/mmu.c),需启用 CONFIG_USERSPACE 且生命周期内创建超过 255 个内存域;具体受影响版本范围暂无公开信息。
漏洞详情
漏洞类型为资源标识符分配不当导致的 TLB 隔离失效。ASID 是区分不同内存域缓存翻译的唯一标签,域私有映射以非全局(MT_NG)方式安装。z_arm64_swap_ptables() 仅在切换前后域 ASID 相同时刷新 TLB,无法覆盖经第三个域间接复用 ASID 的情况,例如 A 与 C 共享 ASID 时调度 A->B->C 不会触发刷新,A 的 TLB 条目在 C 运行时仍驻留。
利用条件与风险
利用前提是 ARM64 上启用 CONFIG_USERSPACE 的应用创建超过 255 个内存域;SMP 下两个存活域共享 ASID 还可能同时驻留于两个 CPU,实战中可导致内存隔离被绕过。
修复建议
官方修复方案暂无公开信息;临时缓解措施包括限制内存域创建数量、避免 ASID 回绕,或对域切换路径强制刷新 TLB。
The ARM64 MMU back-end allocated address space identifiers (ASIDs) for memory domains with a bare round-robin counter in arch_mem_domain_init() (arch/arm64/core/mmu.c). VM_ASID_BITS is 8, so only 255 ASIDs exist; once the counter wrapped, arch_mem_domain_init() could hand an ASID to a new domain while a still-live domain held the same one. Domain-private mappings are installed non-global (MT_NG), so the ASID is the only tag separating one domain’s cached translations from another’s in the TLB.
The context-switch path in z_arm64_swap_ptables() only flushes the TLB when the outgoing and incoming domains carry the same ASID, which does not cover a duplicate reached through a third domain: for domains A and C sharing an ASID and an unrelated domain B, the schedule A -> B -> C never takes the flush branch, so the ASID-tagged entries A populated remain resident while C runs. Under SMP two live domains sharing an ASID can additionally be resident on two CPUs at once, which the architecture does not allow for distinct translation-table sets.
Triggering the wrap requires a CONFIG_USERSPACE application on ARM64 that creates more than 255 memory domains over its lifetime; k_mem_domain_init() and k_mem_domain_deinit() are supervisor-only APIs and are not exposed as syscalls, so an unprivileged thread cannot drive the counter directly. Once two live domains alias, however, a user-mode thread in one domain can read and write memory belonging to the other domain’s partitions and thread stacks with that domain’s permissions, defeating the memory-domain isolation boundary.
The fix scans the live domain_list before assigning an ASID, advances the round-robin counter past ASIDs already in use, and returns -ENOMEM when all are taken, so domain creation fails closed instead of silently aliasing.