Impact
KVM on ARM64 applies cacheable memory attributes unconditionally when creating virtual namespace context registers, even if the page frame number does not point to normal memory. This mismatch can trigger a hardware SError during writeback, causing the kernel to panic or reboot. The flaw represents a memory‑attribute abuse that leads to a system‑wide denial of Service.
Affected Systems
All Linux kernel installations that contain the KVM virtualization subsystem on ARM64 are potentially affected. The description does not list specific kernel versions, so any revision that has not applied the defensive rejection of non‑memory PFNs is at risk. Information on exact affected releases is unavailable in the supplied data.
Risk and Exploitability
The CVSS score of 9.3 denotes a critical vulnerability. The EPSS score is below 1%, suggesting a low current exploitation probability, but the flaw requires hypervisor‑level control to create a VNCR mapping. An attacker who can manipulate the guest KVM may trigger the fault, causing the host to crash. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation, yet the severity of the crash and absence of mitigations suggest a high risk if not patched.
OpenCVE Enrichment