Junglewise Threat Intelligence

CVE-2026-64286: Linux Kernel KVM pointer dereference in arm64 vCPU flushing

CVE-2026-64286 · Severity: info · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's virtualization component (KVM) for ARM64 systems. The issue occurs when the system manages virtual machine processors, potentially allowing a local user to cause a system crash or instability by triggering an invalid memory access within the hypervisor. This could disrupt cloud services or other environments relying on hardware virtualization.

Technical details

A vulnerability exists in the pKVM (Protected KVM) implementation for arm64 within the Linux kernel. The function `flush_hyp_vcpu()` copies the host vCPU context into the hypervisor's private vCPU context verbatim. Because `ctxt_to_vcpu()` expects the `__hyp_running_vcpu` field to be NULL in guest contexts to correctly resolve the vCPU via `container_of()`, a non-NULL value provided by the host can lead to an unintended pointer dereference at Exception Level 2 (EL2). This occurs because the hypervisor does not enforce the NULL requirement during the context copy. The fix involves explicitly clearing the `__hyp_running_vcpu` pointer after the copy operation.

Affected products

  • Linux Linux Kernel 6.2 to 7.1.4

Timeline

  • 2026-07-25: disclosed
  • 2026-07-25: patched

References

Related threats