Impact
The Linux kernel’s virtual generic interrupt controller (VGIC) on ARM64 KVM environments can double‑deactivate a physical interrupt that has already been cleared by hardware. When this occurs in a nested VM, the additional deactivation triggers a hardware erratum on AmpereOne processors, causing the CPU to lose the pending interrupt state and suppress the delivery of future interrupts.
Affected Systems
Linux kernel installations running KVM on ARM64 that include the VGIC code are affected, with the erratum manifesting specifically on AmpereOne hardware. Version information is not specified in the advisory; the vulnerability is described as “resolved” by a kernel commit, but the exact kernel release containing the fix is not named.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is fewer than 1 %, suggesting a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The advisory does not specify an attack vector or privilege level, and no public exploit is documented; therefore the risk is theoretical and likely limited to scenarios where a nested VM can trigger the double‑deactivation on vulnerable AmperOne hosts.
OpenCVE Enrichment