The ARM64 MMU back-end allocated address space identifiers (ASIDs) for memory domains with a bare round-robin counter in arch_mem_domain_init() (arch/arm64/core/mmu.c). VM_ASID_BITS is 8, so only 255 ASIDs exist; once the counter wrapped, arch_mem_domain_init() could hand an ASID to a new domain while a still-live domain held the same one. Domain-private mappings are installed non-global (MT_NG), so the ASID is the only tag separating one domain's cached translations from another's in the TLB. The context-switch path in z_arm64_swap_ptables() only flushes the TLB when the outgoing and incoming domains carry the same ASID, which does not cover a duplicate reached through a third domain: for domains A and C sharing an ASID and an unrelated domain B, the schedule A -> B -> C never takes the flush branch, so the ASID-tagged entries A populated remain resident while C runs. Under SMP two live domains sharing an ASID can additionally be resident on two CPUs at once, which the architecture d
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-19574 is a memory isolation vulnerability in ARM64 systems where the Memory Management Unit (MMU) backend improperly manages Address Space Identifiers (ASIDs) using a bare round-robin counter. With only 255 available ASIDs, the counter wraps and reassigns the same ASID to different memory domains while previous domains remain active. Since these domains use non-global Translation Lookaside Buffer (TLB) entries tagged only by ASID, an attacker can exploit ASID collision to access another domain's cached memory translations. This breaks a fundamental security boundary in virtualized and containerized environments, affecting any ARM64-based system (including mobile devices, edge computing, cloud infrastructure, and embedded systems) running the vulnerable Zephyr RTOS or similar kernels. An attacker with local code execution in one domain can read or modify memory belonging to isolated domains, escalating privileges and compromising confidentiality and integrity.
Casky's threat detection would focus on behavioral patterns consistent with cross-domain memory access exploitation. While MITRE ATT&CK techniques are marked N/A for this CVE (as it's a low-level architectural flaw rather than a discrete attack technique), practitioners would observe findings aligned with T1134 (Process Injection/Execution Context Manipulation) and T1040 (Traffic Capture) patterns—specifically, unauthorized memory reads from protected domains that should be isolated by ASID boundaries. Casky's extended reasoning would correlate suspicious memory access patterns, TLB coherency anomalies, and domain boundary violations against the 754 mapped security skills to surface indicators such as: unexpected cross-domain memory references, timing-based cache side-channels revealing TLB collisions, and privilege escalation attempts following ASID reuse windows. Security practitioners reviewing Casky findings would see clustering of memory access violations coinciding with application restarts or domain lifecycle events (the exact moments ASID reassignment occurs), allowing them to detect exploitation attempts and validate that their ARM64 systems are patched against this isolation bypass.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-19574. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation