Impact
In KVM for ARM64, the TLB invalidation routine compared a virtual address range based on the TLB entry and the TLBI instruction. The comparison did not handle address rollover, treating the end of the range incorrectly as a zero address, which caused the invalidation to fail for the last page or block of the TTBR1 virtual address space. Consequently, stale TLB entries could remain, allowing virtual machines to access memory that should have been revalidated, potentially leading to memory corruption or escalation of privileges within the host.
Affected Systems
All Linux kernels that use the KVM driver on ARM 64 bit architectures are affected. No specific version information is provided, so any derivative of the Linux kernel that includes the buggy arm64 KVM TLB logic is vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that, at the time of this assessment, the likelihood of exploitation is very low, and the vulnerability is not listed in CISA’s KEV catalog. The problem is strictly in the kernel’s internal address comparison logic, so an exploit would most likely require the attacker to control or influence the virtual memory mapping of a VM or have other privileged access to the host. The attack surface is confined to ARM64 KVM usage, making it niche but severe for impacted environments.
OpenCVE Enrichment