Impact
In nested KVM on ARM64, an erroneous restoration of the SPSR_EL2 register in kvm_hyp_handle_mops() caused the processor state to be written directly from a synthetic value, bypassing required translation. This fault enables a nested virtual machine to manipulate host CPU state on exit, potentially allowing it to gain privileges beyond its sandbox and escape isolation.
Affected Systems
All Linux kernel releases that include the KVM module for ARM64 are impacted, particularly when nested virtualization is in use. The vulnerability exists in the core KVM hypervisor code handling MOPS (Memory Operation) exceptions.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of < 1% reflects a very low but non-zero likelihood of exploitation, and it is not listed in CISA KEV. Exploitation requires an attacker to trigger a MOPS exception within a nested VM, a capability that is generally limited to guest code but, if achieved, would allow the guest to manipulate the host's CPU state and potentially escape isolation. The likely attack vector is through privileged guest code manipulating nested VM execution paths.
OpenCVE Enrichment
Debian DLA
Debian DSA