Impact
The vulnerability occurs in the Linux kernel's KVM arm64 VGIC v3 implementation, where vgic_v3_save_pending_tables() iterates over the LPI xarray and dereferences a struct vgic_irq without taking a stable reference. This race opens a use‑after‑free window that can corrupt kernel memory and, if exploited, can lead to arbitrary code execution with host kernel privileges. The vulnerability is a classic use‑after‑free and race condition that sits entirely in kernel space, meaning any malicious guest can target it with privileged guest drivers.
Affected Systems
Linux kernels running on arm64 with KVM and the virtual generic interrupt controller (vgic v3) are impacted. The issue is present in all kernel versions that contain the flawed vgic_v3_save_pending_tables() logic, regardless of distribution, until the fix is applied.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity. However, the EPSS score is below 1 %, showing that, as of this analysis, exploitation is not widely observed. The vulnerability is not listed in the CISA KEV catalog. The attack vector is internal to the hypervisor: a guest that can trigger an ITS discard or a cached injection path can race with the host’s table save routine, potentially leading to kernel memory corruption. Users running virtual machines on affected hosts should consider this risk high if they cannot immediately update the kernel.
OpenCVE Enrichment