Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save

MAPC with V=0 drops ite->collection but leaves the ITE on the device's
ITT list, and vgic_its_save_ite() dereferences it unconditionally. A
guest that issues MAPD, MAPTI and then MAPC(V=0) therefore oopses the
host when the VMM issues KVM_DEV_ARM_ITS_SAVE_TABLES to migrate it.
That sequence is UNPREDICTABLE per the architecture, but KVM already
handles the resulting state in the translate, MOVI and DISCARD paths.

Save a zeroed entry, which vgic_its_restore_ite() reads back as
invalid. Skipping the ITE instead would leave the ITT slot holding
whatever is in guest memory, and restore rejects an entry naming a
collection the restored collection table does not have.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (host crash due to kernel oops)
Action: Patch promptly
AI Analysis

Impact

The vulnerability is a NULL pointer dereference in the vgic-its component of the KVM arm64 hypervisor. When a guest issues MAPD, MAPTI, and then MAPC(V=0) followed by a KVM_DEV_ARM_ITS_SAVE_TABLES operation during migration, the kernel dereferences an invalid pointer, causing an oops and bringing the host down. The result is a loss of availability and potential interruption of services running on the host.

Affected Systems

The flaw exists in all Linux kernel releases that have not incorporated the fix commit 36df368861d2664291298feeb37dfef43fcae670. It affects KVM running on arm64 architectures and thus any Linux hosts using that kernel and hypervisor configuration. Exact version coverage is not specified in the advisory, so all releases prior to applying that commit are considered vulnerable.

Risk and Exploitability

With a CVSS score of 7.1, the vulnerability is of high severity. The EPSS score of less than 1% denotes a low likelihood of exploitation, and it is not currently listed in the CISA KEV catalog. The attack requires a guest to execute a specific, non‑canonical sequence of memory operations that is considered unpredictable by the architecture. Even so, once triggered it would crash the host, making it a serious, though unlikely, denial‑of‑service risk.

Generated by OpenCVE AI on September 18, 2026 at 07:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a Linux kernel that contains the commit 36df368861d2664291298feeb37dfef43fcae670 or apply the corresponding patch to guard against the NULL dereference in vgic_its_save_ite().
  • Rebuild or reload the KVM kernel modules to ensure the updated code is loaded, then restart the host or reload the KVM service to activate the fix.
  • If an immediate kernel upgrade is not feasible, restrict or disable the KVM_ARM_ITS_SAVE_TABLES operation for guests, or isolate vulnerable guests and avoid migration paths that trigger the MAPC(V=0) sequence.

Generated by OpenCVE AI on September 18, 2026 at 07:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 12:15:00 +0000


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save MAPC with V=0 drops ite->collection but leaves the ITE on the device's ITT list, and vgic_its_save_ite() dereferences it unconditionally. A guest that issues MAPD, MAPTI and then MAPC(V=0) therefore oopses the host when the VMM issues KVM_DEV_ARM_ITS_SAVE_TABLES to migrate it. That sequence is UNPREDICTABLE per the architecture, but KVM already handles the resulting state in the translate, MOVI and DISCARD paths. Save a zeroed entry, which vgic_its_restore_ite() reads back as invalid. Skipping the ITE instead would leave the ITT slot holding whatever is in guest memory, and restore rejects an entry naming a collection the restored collection table does not have.
Title KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:03.242Z

Reserved: 2026-09-11T19:38:34.774Z

Link: CVE-2026-89912

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:00.230

Modified: 2026-09-16T15:18:17.413

Link: CVE-2026-89912

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T00:00:00Z

Links: CVE-2026-89912 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses