Impact
The flaw allows a virtual machine to encode a TLB invalidation range that exceeds the architectural limit by adding an arbitrary virtual address to the range. This overflow enables the guest to corrupt kernel memory when the hypervisor performs the invalidation. The result is potential arbitrary code execution or escalation of privileges within the host. The vulnerability is a classic integer/bounds overflow that can be exploited locally by a guest.
Affected Systems
The affected system is the Linux kernel running KVM on ARM64 architectures. No specific kernel version numbers are supplied in the CNA data, so all current ARM64 kernels that have not yet applied the patch are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.9 indicates a high severity with medium to high impact. The EPSS score of less than 1% shows a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local guest operating system in a virtualised environment using KVM where the guest can generate the overflow via the TLB invalidation interface. The flaw requires that the hypervisor naively calculate the range without capping it to the architectural limit, which occurs in the kernel’s TLBI path for arm64.
OpenCVE Enrichment