Impact
A race condition in the KVM arm64 NV extension can trigger a null pointer dereference when a virtual CPU is not yet online; the model that handles VNCR TLB invalidation fails to check whether the pseudo‑TLB has been allocated, potentially causing the kernel to crash and denying service to the virtual machine and host.
Affected Systems
The flaw affects the Linux kernel on ARM64 platforms that use KVM. It is present in all kernel releases prior to the commit that introduced a safe iterator for the VNCR functions; no specific version numbers are listed in the data, so any kernel build before the fix is vulnerable.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low probability of real‑world exploitation. The CVSS score of 5.5 reflects a moderate impact. The vulnerability appears to be exploitable from within the host system. Based on the description, it is inferred that an attacker would need privileged access to the KVM hypervisor to trigger the null pointer dereference. The issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment