Impact
KVM on ARM64 applies cacheable memory attributes unconditionally when creating virtual namespace context registers, even if the page frame number does not point to normal memory. This mismatch can trigger a hardware SError during writeback, causing the kernel to panic or reboot. The flaw represents a memory‑attribute abuse that leads to a system‑wide denial of service.
Affected Systems
All Linux kernel installations that contain the KVM virtualization subsystem on ARM64 are potentially affected. The description does not list specific kernel versions, so any revision that has not applied the defensive rejection of non‑memory PFNs is at risk. Information on exact affected releases is unavailable in the supplied data.
Risk and Exploitability
The CVSS score is not provided and EPSS is unavailable, but the bug resides in privileged kernel code that requires the ability to instruct KVM to create a VNCR mapping. An attacker with hypervisor‑level control can potentially trigger the fault, causing a host reboot or loss of service. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation, yet the severity of the crash and absence of mitigations suggest a high risk if not patched.
OpenCVE Enrichment