Impact
The vulnerability exists in the KVM implementation for arm64 GICv2, where vgic_v2_deactivate() passes the INTID a guest wrote to GICV_DIR straight to vgic_get_vcpu_irq(), and treats a failed lookup as a "can't happen" condition with WARN_ON_ONCE(). The guest can make it happen at will; for any INTID outside of the implemented SGI, PPI and SPI ranges the lookup returns NULL, since GICv2 has no LPIs. A guest running with EOImode==1 writing such an INTID to GICV_DIR triggers the WARN and, if panic_on_warn is enabled on the host, can cause the host to panic, resulting in a loss of availability for all users on that host. This weakness is an instance of CWE-617.
Affected Systems
Affected version information is not available. All systems running a Linux kernel that hosts KVM on arm64 and uses the GICv2 driver before the patch commit are as Linux:Linux, regardless of vendor, as the vulnerability is in the upstream kernel source.
Risk and Exploitability
The CVSS score of 4.7 and an EPSS score of less than 1% imply a very low likelihood of exploitation and no known exploits are reported in CISA’s KEV catalog. An attacker controlling a KVM guest can trigger the warning and, if panic_on_warn is enabled, crash the host, leading to a denial of service. The exploitation path requires the guest to write an out‑of‑range INTID to GICV_DIR with EOImode set, a capability typically granted to privileged guests.
OpenCVE Enrichment