PT-2026-64508 · Linux+3 · Linux Kernel+3

CVE-2026-64287

·

Published

2026-07-25

·

Updated

2026-09-08

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the KVM arm64 component where the flush hyp vcpu() function copies the host vGIC state into the hyp's private vCPU without validating the used lrs value. Because used lrs is used as a loop bound for saving and restoring vGIC list registers, a value provided by the host can be used at EL2 to index the vgic lr[] array and access ICH LR<n> EL2. This occurs because the function copies vgic v3 verbatim and fails to enforce that the value remains within the number of implemented list registers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:64808
AZL-93875
CVE-2026-64287
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu