Junglewise Threat Intelligence

CVE-2026-23425: Linux kernel KVM arm64 state corruption in pKVM ID register initialization

CVE-2026-23425 · Severity: high · CVSS 8.8 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's virtualization component (KVM) on ARM64 systems could allow a local user to cause system instability or state corruption. The issue occurs when the system fails to properly initialize internal registers for virtual machines, potentially leading to incorrect data being saved or restored. This could impact the reliability and security of virtualized environments running on affected hardware.

Technical details

A flaw in the KVM arm64 implementation for non-protected pKVM guests leads to improper ID register initialization. Specifically, the pkvm_init_features_from_host() function copies the KVM_ARCH_FLAG_ID_REGS_INITIALIZED flag from the host without actually initializing the underlying id_regs data. This causes feature detection checks at EL2 to fail, resulting in certain system registers (such as TCR2_EL1, PIR_EL1, and POR_EL1) not being correctly saved or restored during world switches. An attacker with local access could exploit this to cause state corruption or potentially escalate privileges. Patches have been released for various stable kernel branches to ensure ID registers are explicitly copied and flags are correctly managed during VM initialization.

Affected products

  • Linux Linux kernel 6.14, 6.18.17, 6.19.7

Timeline

  • 2026-02-13: patched: Initial patch submitted by Fuad Tabba
  • 2026-04-03: disclosed: CVE-2026-23425 published

References

Related threats