Impact
The vulnerability is a NULL pointer dereference in the vgic-its component of the KVM arm64 hypervisor. When a guest issues MAPD, MAPTI, and then MAPC(V=0) followed by a KVM_DEV_ARM_ITS_SAVE_TABLES operation during migration, the kernel dereferences an invalid pointer, causing an oops and bringing the host down. The result is a loss of availability and potential interruption of services running on the host.
Affected Systems
The flaw exists in all Linux kernel releases that have not incorporated the fix commit 36df368861d2664291298feeb37dfef43fcae670. It affects KVM running on arm64 architectures and thus any Linux hosts using that kernel and hypervisor configuration. Exact version coverage is not specified in the advisory, so all releases prior to applying that commit are considered vulnerable.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability is of high severity. The EPSS score of less than 1% denotes a low likelihood of exploitation, and it is not currently listed in the CISA KEV catalog. The attack requires a guest to execute a specific, non‑canonical sequence of memory operations that is considered unpredictable by the architecture. Even so, once triggered it would crash the host, making it a serious, though unlikely, denial‑of‑service risk.
OpenCVE Enrichment