Executive brief
A vulnerability was identified in the Linux kernel's virtualization component (KVM) for ARM64 systems. The issue occurs when the system manages virtual interrupt controllers, where it fails to properly check the boundaries of certain internal registers. This could potentially allow a guest operating system to cause a system crash or instability on the host machine.
Technical details
A vulnerability in flush_hyp_vcpu() in the Linux kernel's KVM arm64 implementation allows for an out-of-bounds access. The function copies the host vGIC state into the hypervisor's private vCPU without validating the 'used_lrs' value. Because 'used_lrs' is used as a loop bound to index the vgic_lr[] array and access ICH_LR<n>_EL2 registers at EL2, an unconstrained value provided by the host can lead to out-of-bounds memory access. This affects systems using protected KVM (pKVM). The fix involves clamping the used_lrs value to the actual number of implemented list registers (hyp_gicv3_nr_lr).
Affected products
- Linux Linux Kernel 6.2 to 7.1.4
Timeline
- 2026-07-25: advisory: CVE-2026-64287 published by NVD
- 2026-07-24: patched: Fix committed to stable kernel tree
References
- https://git.kernel.org/stable/c/2c5e72b9fbf83fdfa724e9f1af0f418ccf8739b8
- https://git.kernel.org/stable/c/7fca3fcef81c713bc82a37bf741e0f28e6d04a6f
- https://git.kernel.org/stable/c/8cc8bbbfab14c22c5551d0dd19b208a44b141c76
- https://git.kernel.org/stable/c/9fa301d8298778dd799fa4dcf7a7f440715d146e
- https://git.kernel.org/stable/c/c646431865f4b1a5b14067233fa27b11e05e0d46