Executive brief
The Linux kernel's KVM hypervisor for ARM64 processors contains a race condition in interrupt handling that allows concurrent operations to corrupt or leak shared data structures. An attacker with the ability to run guest virtual machines could exploit this to cause system crashes, data corruption, or denial of service on the host system.
Technical details
The vulnerability is a use-after-free and data corruption race condition in the KVM arm64 virtual GIC (Generic Interrupt Controller) LPI (Locality-specific Peripheral Interrupt) handling. The bug occurs between the reference count drop and xarray eviction of an LPI structure in dist->lpi_xa—these operations are not atomic. An attacker controlling a guest can issue concurrent LPI DISCARD and MAPTI operations from multiple vCPUs, causing a newly registered LPI to be deleted from the xarray or an old LPI to be leaked. The vulnerability requires guest execution capabilities and can result in host kernel memory corruption and denial of service. The fix moves the refcount drop inside the xarray lock (direct path) and updates vgic_add_lpi() to handle eviction responsibility (deferred path).
Affected products
- Linux Linux kernel prior to fix (version not specified in advisory)
Timeline
- 2026-08-15: disclosed