Impact
The flaw in the KVM arm64 subsystem causes the VNCR abort handler to misinterpret certain translation failures, allowing a guest to trigger a Secure Exception Abort (SEA) in the host. This injection could let the guest execute privileged code or corrupt kernel state; the exact privilege escalation outcome is inferred from the description rather than explicitly stated.
Affected Systems
All Linux arm64 kernels that include the buggy kvm_translate_vncr() implementation before the patch, across mainstream distributions and custom kernels used to host KVM guests on Arm‑64 platforms.
Risk and Exploitability
The CVSS score of 7.1 denotes a moderate severity. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA KEV. Attackers would need to launch the vulnerability from an untrusted guest that can provoke a late failure in S1 translation. The overall risk is moderate to high for environments running untrusted guests or lacking hardening controls.
OpenCVE Enrichment