Executive brief
A vulnerability was identified in the Linux kernel's virtualization component (KVM) for ARM64 systems using nested virtualization. When a specific type of memory operation (MOPS) occurs, the system incorrectly handles the processor's state, which could lead to instability or unexpected behavior in virtual machines. This issue primarily affects environments where one virtual machine is running another virtual machine (nested virtualization).
Technical details
A vulnerability in the Linux kernel's KVM arm64 implementation involves the 'kvm_hyp_handle_mops()' function. When resetting the single-step state machine during a MOPS (Memory Operations) exception rewind, the handler modifies 'vcpu_cpsr()' and writes it directly to hardware. In nested virtualization (NV), 'vcpu_cpsr()' contains a synthetic value for vEL2 that requires translation before hardware insertion. The lack of this translation results in incorrect state restoration. The fix involves directly modifying the hardware SPSR_EL2 register to avoid synthetic state corruption. This issue affects ARM64 systems with nested virtualization enabled.
Affected products
- Linux Linux 6.7 to 6.12.97, 6.18.40, 7.1.5
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory