Impact
Based on the description, it is inferred that the Linux kernel KVM driver for ARM64 mishandles the mapping of the L1 VNCR when the backing physical frame number is marked read‑only. Because the kernel relied only on guest stage‑1 permissions, a guest could trigger write attempts to a read‑only endpoint, resulting in an improper mapping that can lead to memory corruption or the exposure of host memory through early returns and page leaks. The flaw does not depend on a specific kernel configuration and thus applies to any KVM‑enabled environment that uses L1 VNCR with read‑only backing pages.
Affected Systems
Based on the description, it is inferred that the vulnerability affects the Linux kernel KVM subsystem on ARM64 architectures. Version information is not explicitly listed in the advisory, but the fix appears in recent kernel commits, so all current and older releases before the patch are potentially impacted.
Risk and Exploitability
Based on the description, it is inferred that the potential consequence is privilege escalation from the guest to the host or unintended data leakage. The CVSS score is not provided, and EPSS data is unavailable, but the absence of the vulnerability from CISA KEV suggests the exploit level is not widely known. Nevertheless, the attack would require a vulnerable guest to trigger a permission fault through the L1 VNCR; sophisticated guests or compromised workloads could exploit this, so the risk remains significant for environments with untrusted virtual machines.
OpenCVE Enrichment