Impact
The Linux kernel’s KVM arm64 implementation contains an obsolete global VNCR mapping counter that determines whether a virtual-to-physical mapping is present in L0 during TLB invalidation. The counter logic can mistakenly report absence of a mapping, leading to missing or incorrect TLB invalidation. Based on the description, it is inferred that such incorrect handling could result in stale mapping entries that expose data across virtual machine contexts, potentially enabling information disclosure or privilege escalation. The weakness appears to be an improper memory consistency handling flaw.
Affected Systems
All Linux kernel releases that include the legacy VNCR mapping counter before its removal commit are affected. This applies to KVM running on ARM64 architectures, regardless of distribution. The patch is present in all kernel releases after the commit referenced in the advisory. Users of older kernels must upgrade to a release that contains the fix.
Risk and Exploitability
The vulnerability receives a CVSS score of 9.3, indicating critical severity. Its EPSS score is less than 1 %, suggesting that active exploitation is unlikely but still possible in targeted environments. The issue is not listed in the CISA KEV catalog. Attackers would need to run a malicious guest or possess kernel‑level access to trigger the incorrect TLB handling, making the attack vector local to the host hypervisor. Based on the description, it is inferred that the attacker must exploit the L1 guest’s TLB operations or achieve kernel-level escalated privileges on the host. Given the high severity, any vulnerable environment should be considered at risk until the patch is applied.
OpenCVE Enrichment