Impact
A flaw in the Linux kernel's arm64 KVM code incorrectly handles an S1 walk level that is set to a negative sentinel value when the MMU is disabled. The level value is cast to an unsigned byte, causing the bit-shift function to interpret the value as zero. Consequently the calculated TLB invalidation size is zero and the TLB entries that should be flushed are left intact. A guest VM that is able to execute code could therefore read or modify the kernel memory or other guests' memory that should have been invalidated, allowing the guest to gain host privileges or interfere with other VMs. The weakness arises from a signed-to-unsigned conversion error and deliberate lack of validation, corresponding to CWE-190.
Affected Systems
All Linux kernels that use the KVM implementation for arm64, irrespective of release version, are potentially affected because the code paths involving the S1_MMU_DISABLED state are part of the default KVM code base. No specific kernel version numbers are cited, so any kernel that has not applied the patch commit that fixes the negative walk level handling remains vulnerable.
Risk and Exploitability
The CVSS score of 9.3 gives this vulnerability critical severity, but the EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis. Because the issue requires the attack surface of a guest VM that can run code inside the hypervisor, the exploitability hinges on having unrestricted code execution within the VM. The vulnerability is not listed in the CISA KEV catalog, suggesting that no publicly known exploits exist yet. Nonetheless, the combination of a high severity score and the capability to potentially read or write protected memory makes this issue a high priority for patching.
OpenCVE Enrichment