Junglewise Threat Intelligence

CVE-2026-80699: Linux kernel KVM arm64 vgic double-deactivate in nested context

CVE-2026-80699 · Severity: info · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's KVM (virtualization subsystem) on ARM64 processors contains a bug in interrupt handling that can cause CPUs to lose pending interrupt state on AmpereOne processors. When a virtual machine nested within another virtual machine attempts to deactivate interrupts, a redundant operation can trigger a hardware errata that prevents future interrupts from being delivered, potentially causing virtual machine workloads to become unresponsive.

Technical details

The vulnerability is a logic error in the vgic_v3_deactivate() function in arch/arm64/kvm/vgic/vgic-v3.c. In nested virtualization scenarios, physical interrupts are already deactivated via the HW bit in the List Register (LR), but the kernel was performing an additional deactivation through ICC_DIR_EL1 or ICC_EOIR1_EL1 instructions. While this double-deactivation is typically harmless, it triggers AmpereOne errata AC03_CPU_57 and AC04_CPU_29, where deactivating a non-active interrupt that is the highest priority pending interrupt causes the CPU to lose interrupt pending state and prevents delivery of future interrupts. The fix adds a check to skip the physical interrupt deactivation when in nested virtualization state (via vgic_state_is_nested()). This is a kernel-level workaround for a CPU-specific hardware errata and requires no user interaction or special configuration.

Affected products

  • Linux Linux kernel 5.x, 6.x, 7.x (specific stable branches)

Timeline

  • 2026-07-14: disclosed: Patch authored by D Scott Phillips
  • 2026-07-21: patched: Merged by Marc Zyngier
  • 2026-08-09: other: Backported to stable kernel branches

References

Related threats