Impact
The vulnerability is a missing sign extension in the KVM arm64 code path used for range‑based TLB invalidation. Because the virtual address is not sign‑extended before converting it to a PA during an S2 TLBI, the translation can overflow the PA bits. The consequence is that an attacker can cause the hypervisor to invalidate or modify memory at an unintended address, potentially corrupting host memory or breaking isolation between virtual machines. In the worst case, this attack can lead to privilege escalation from a guest VM to the host or denial of service for all VMs.
Affected Systems
Affected systems are Linux kernels that include the KVM module for the arm64 architecture. No exact kernel version range is supplied, but any kernel that uses the KVM arm64 range‑based TLBI code prior to the commit that added the sign extension is vulnerable. This applies to servers or devices running Linux with KVM virtualization on ARM64 CPUs.
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity condition. The EPSS score is below 1 %, suggesting a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, the vulnerability remains exploitable locally on a host that runs vulnerable KVM, and an attacker would benefit from control over a guest VM. The required conditions for exploitation are likely to be a privileged guest or a trusted application that can trigger S2 TLBI with an arbitrary address, and the attack vector is inferred to be local to the host.
OpenCVE Enrichment