Linux Kernel arm64 Qualcomm Monaco Gunyah Metadata Insufficient Reservation CVE-2026-43347 (High) -DC-Oct2026-2730

Listen to this Post

CVE-2026-43347 is a high-severity vulnerability in the Linux kernel affecting arm64-based Qualcomm Monaco platforms, where improper memory reservation handling for hypervisor-owned regions allows the kernel to inadvertently access protected Gunyah hypervisor memory. The issue manifests as spurious “Synchronous External Abort” exceptions with ESR value 0x96000010, leading to kernel crashes, instability, and denial of service conditions on affected systems. The root cause lies in a critical discrepancy between the actual hypervisor memory allocation and the EFI memory map reported by firmware. Qualcomm’s hypervisor correctly identifies a 512 KiB memory range starting at physical address 0x91a80000 as hypervisor-owned, yet the firmware’s EFI memory map only properly reserves the first 288 KiB of this region (0x91a40000–0x91a87fff). The remaining 224 KiB portion (0x91a88000–0x91afffff) is incorrectly marked as conventional memory available for general kernel use. This misalignment creates a dangerous scenario where the Linux kernel’s memory allocator may assign page frame numbers (PFNs) within the hypervisor-owned region, resulting in fatal aborts when kernel code attempts to access these privileged addresses. The vulnerability operates at the intersection of hardware virtualization and kernel memory management, violating fundamental security principles of hypervisor isolation. According to VulDB analysis, this aligns with CWE-1288 (inadequate memory protection mechanisms) and ATT&CK technique T1068, representing a memory management oversight where kernel space fails to properly isolate hypervisor-privileged regions. The patch adds a reserved-memory carveout for the Gunyah hypervisor metadata at 0x91a80000 (512 KiB) and marks it as no-map so Linux does not map or allocate from this area. Systems may experience unexpected reboots or kernel panics during normal operation when memory allocation touches these protected regions. The vulnerability is rated 7.5 HIGH by kernel.org with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a network-accessible, low-complexity issue that primarily impacts availability through denial of service.

DailyCVE Form:

Platform: Linux Kernel
Version: 6.18.23/6.19.13
Vulnerability : Hypervisor isolation bypass
Severity: High
date: 2026-05-08

Prediction: 2026-06-15

What Undercode Say:

Check if affected Qualcomm Monaco platform
dmesg | grep -i "Synchronous External Abort"
dmesg | grep -i "0x96000010"
dmesg | grep -i "qhee_hyp_assign_remove_memory"
Verify current kernel version
uname -r
Check EFI memory map reservation
cat /proc/iomem | grep -i "91a80000"
cat /proc/iomem | grep -i "91a88000"
Inspect device tree memory reservations
find /proc/device-tree -name "reserved-memory" -type d
cat /proc/device-tree/reserved-memory//reg | xxd
Check for Gunyah hypervisor presence
dmesg | grep -i "gunyah"
dmesg | grep -i "hyp version"
Monitor kernel crashes
journalctl -k | grep -i "abort|panic|oops"
Parse EFI memory map for affected region
import re
def check_efi_reservation(efi_output):
"""Check if 0x91a88000-0x91afffff is incorrectly conventional"""
pattern = r'0x000091a8(8000|9000|a000|b000|c000|d000|e000|f000)'
for line in efi_output.split('\n'):
if re.search(pattern, line, re.IGNORECASE):
if 'Conventional' in line:
print(f"[!] Vulnerable: {line.strip()}")
elif 'Reserved' in line:
print(f"[+] Patched: {line.strip()}")
Parse boot log for hypervisor assignment
def check_hyp_assignment(boot_log):
"""Verify hypervisor-owned region size"""
match = re.search(r'qhee_hyp_assign_remove_memory:\s(0x[0-9a-f]+)/(0x[0-9a-f]+)',
boot_log, re.IGNORECASE)
if match:
addr, size = match.groups()
print(f"Hypervisor region: {addr} size {size}")
if int(size, 16) == 0x80000:
print("[!] Full 512 KiB region reported by hypervisor")
reserved = re.findall(r'efi: (0x000091a[0-9a-f]+)-(0x000091a[0-9a-f]+) [Reserved',
boot_log)
if reserved:
start, end = reserved[bash]
span = int(end, 16) - int(start, 16) + 1
print(f"EFI reserved span: {hex(span)} bytes")
if span < 0x80000:
print("[!] Under-reserved: vulnerable to CVE-2026-43347")

Exploit: (Educational Purposes!)

Demonstrating the vulnerability condition (educational only)
Simulate allocator behavior with undersized reservation
Step 1: Verify the discrepancy exists
echo "=== Checking hypervisor vs EFI memory map ==="
dmesg | grep "qhee_hyp_assign_remove_memory"
dmesg | grep "0x000091a88000"
Step 2: Show what the allocator sees
cat /proc/iomem | awk '/91a[0-9a-f]0000/ {print}'
Step 3: Trigger allocation pressure in the affected range
(Requires root and is for educational demonstration only)
stress-ng --vm 4 --vm-bytes 512M --timeout 60s
Step 4: Monitor for synchronous external aborts
dmesg -w | grep -E "Synchronous External Abort|0x96000010|Unable to handle"
// Educational representation of the memory reservation gap
include <stdio.h>
include <stdint.h>
define HYP_BASE 0x91a80000ULL
define HYP_SIZE 0x80000ULL
define EFI_BASE 0x91a40000ULL
define EFI_SIZE 0x48000ULL // 288 KiB - INCORRECT
int main(void) {
uint64_t hyp_end = HYP_BASE + HYP_SIZE;
uint64_t efi_end = EFI_BASE + EFI_SIZE;
printf("Hypervisor-owned: 0x%llx - 0x%llx (%llu KiB)\n",
HYP_BASE, hyp_end - 1, HYP_SIZE / 1024);
printf("EFI reserved: 0x%llx - 0x%llx (%llu KiB)\n",
EFI_BASE, efi_end - 1, EFI_SIZE / 1024);
if (efi_end < hyp_end) {
printf("\n[bash] Gap of %llu KiB exposed to allocator:\n",
(hyp_end - efi_end) / 1024);
printf(" 0x%llx - 0x%llx is marked CONVENTIONAL\n",
efi_end, hyp_end - 1);
printf(" Allocator may assign PFNs in hypervisor region -> FATAL ABORT\n");
}
return 0;
}

Protection: from this CVE

Immediate mitigation: Add reserved-memory carveout to device tree
In arch/arm64/boot/dts/qcom/monaco.dtsi:
reserved-memory {
gunyah_metadata: gunyah-metadata@91a80000 {
reg = <0x0 0x91a80000 0x0 0x80000>;
no-map;
};
};
Rebuild device tree blob
make dtbs
cp arch/arm64/boot/dts/qcom/monaco.dtb /boot/
Verify the reservation is applied after reboot
dmesg | grep -i "gunyah"
dmesg | grep -i "reserved"
cat /proc/iomem | grep -i "gunyah"
Update kernel to patched version
The fix is included in kernel versions after 6.19.13
apt update && apt upgrade linux-image-$(uname -r)
For custom kernels, apply the upstream patch
Subject: arm64: dts: qcom: monaco: Reserve full Gunyah metadata region
Patch adds no-map reserved-memory carveout at 0x91a80000 (512 KiB)
Verification after patching
dmesg | grep "qhee_hyp_assign_remove_memory"
Should show full 512 KiB reservation
cat /proc/iomem | grep "91a80000"
Should show Gunyah metadata region reserved
Monitor for regression
dmesg -w | grep -i "Synchronous External Abort"
Should return no results on patched systems
Check kernel config for hypervisor support
zcat /proc/config.gz | grep -i "GUNYAH|HYPERVISOR"

Impact:

Successful exploitation of CVE-2026-43347 results in complete system crashes and instability on affected Qualcomm Monaco platforms. The vulnerability allows the kernel’s memory allocator to hand out page frame numbers inside the hypervisor-owned Gunyah metadata region, causing fatal synchronous external aborts when kernel code accesses these privileged addresses. Affected systems may experience unexpected reboots, kernel panics, and denial of service conditions during normal operation when memory allocation touches the protected range. The issue bypasses hypervisor isolation principles, creating a path for unauthorized memory access that violates fundamental virtualization security boundaries. The CVSS 3.1 score of 7.5 (HIGH) reflects the network-accessible, low-complexity nature of the vulnerability with primary impact on system availability. While there is currently no public exploit available, the potential for weaponization exists as attackers could deliberately trigger memory pressure conditions to cause repeated system failures. The vulnerability affects arm64-based Qualcomm Monaco platforms running Linux kernel versions up to 6.18.23 and 6.19.13, with the patch adding a reserved-memory carveout for the Gunyah hypervisor metadata at 0x91a80000 (512 KiB) marked as no-map to prevent Linux from mapping or allocating from this area.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top