Impact
The vulnerability is a race condition between the VNCR TLB invalidation routine and the vcpu_put() function in the arm64 KVM implementation. Because the VNCR page mapping state is updated without atomicity, a thread can observe a stale value, trigger an unnecessary unmap, and cause a BUG_ON assertion. The resulting kernel panic results in a complete system crash, interrupting all services running on the host.
Affected Systems
Linux systems running an arm64 kernel that includes the KVM module and have not incorporated the commit that fixes the VNCR race. No specific kernel version ranges are listed, therefore any arm64 kernel build lacking the fix should be considered vulnerable until a patched release is deployed.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not included in CISA’s KEV catalog, suggesting a very low probability of exploitation. However, the impact is severe, as a single triggered race can crash the kernel. The attack vector is inferred to require local access to a host with KVM enabled and the ability to influence virtual CPU state; the exact privilege level needed is not specified.
OpenCVE Enrichment