Executive brief
A vulnerability in the Linux kernel's virtualization component (KVM) for ARM64 processors could allow a virtual machine to bypass intended hardware limits. Specifically, a guest operating system acting as a hypervisor could potentially access Scalable Vector Extension (SVE) features and vector lengths that it should not be permitted to use. This could lead to unauthorized access to processor resources or instability within the virtualized environment.
Technical details
In the Linux kernel's KVM arm64 implementation, a vulnerability exists in how ZCR_EL2 (SVE Control Register) is handled for nested virtualization. When a VHE guest hypervisor updates ZCR_EL2 via ZCR_EL1 (which does not trap), KVM fails to sanitize the value. Upon restoring the SVE context for an L2 guest, this raw, unsanitized value is written directly to the physical hardware. This allows the L2 guest to access Scalable Vector Extension (SVE) vector lengths (VLs) exceeding the limits imposed by the host. The fix involves moving the VL capping logic to the context restore points to ensure hardware is always programmed with a capped value regardless of the accessor used.
Affected products
- Linux Linux 6.11, 7.0.12, 7.1
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory