Impact
A race condition in the Linux kernel’s KVM arm64 TLB invalidation routine can cause a virtual CPU to load a stale or invalid page translation after another virtual CPU updates page tables and issues a TLBI. This flaw may allow a malicious guest to read or execute memory that belongs to another guest or to the host, thereby bypassing isolation guarantees. The weakness is a concurrency error that can lead to uncontrolled memory access or execution, representing a high‑impact privilege escalation scenario.
Affected Systems
This vulnerability affects Linux kernels running on ARM64 architecture that employ KVM virtualization. All systems that use the kernel version with the flawed VNCR invalidation path are impacted, regardless of additional distribution patches. The specific kernel commits referenced by the advisory fix the issue in newer patches; older releases lacking those commits remain vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score of less than 1% suggests that exploitation is unlikely in the near term, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector would be a malicious virtual machine that can perform rapid page table changes. Compromise requires the guest to have control over S1 page tables, which is typically confined within the guest environment, so the exploitation risk is limited to hosts running vulnerable, unpatched kernels.
OpenCVE Enrichment