Executive brief
The Linux kernel's KVM (virtualization subsystem) on ARM64 processors contains a bug in interrupt handling that can cause CPUs to lose pending interrupt state on AmpereOne processors. When a virtual machine nested within another virtual machine attempts to deactivate interrupts, a redundant operation can trigger a hardware errata that prevents future interrupts from being delivered, potentially causing virtual machine workloads to become unresponsive.
Technical details
The vulnerability is a logic error in the vgic_v3_deactivate() function in arch/arm64/kvm/vgic/vgic-v3.c. In nested virtualization scenarios, physical interrupts are already deactivated via the HW bit in the List Register (LR), but the kernel was performing an additional deactivation through ICC_DIR_EL1 or ICC_EOIR1_EL1 instructions. While this double-deactivation is typically harmless, it triggers AmpereOne errata AC03_CPU_57 and AC04_CPU_29, where deactivating a non-active interrupt that is the highest priority pending interrupt causes the CPU to lose interrupt pending state and prevents delivery of future interrupts. The fix adds a check to skip the physical interrupt deactivation when in nested virtualization state (via vgic_state_is_nested()). This is a kernel-level workaround for a CPU-specific hardware errata and requires no user interaction or special configuration.
Affected products
- Linux Linux kernel 5.x, 6.x, 7.x (specific stable branches)
Timeline
- 2026-07-14: disclosed: Patch authored by D Scott Phillips
- 2026-07-21: patched: Merged by Marc Zyngier
- 2026-08-09: other: Backported to stable kernel branches