Impact
The Linux kernel on ARM64 may read the GMID_EL1 register even when the Machine Type Extension (MTE) is disabled. Because that register is not present in that configuration, the CPU raises an undefined instruction exception that the kernel cannot recover from, causing a kernel panic and denying service. The flaw is caused by missing gating of the read based on the CPU’s ID_AA64PFR1_EL1 value and the CONFIG_ARM64_MTE flag. The likely attack vector is a KVM virtual machine or an attacker that can trigger CPU hot‑plug or configuration changes, as the issue is triggered when a CPU is offlined and brought back online or when KVM sets HCR_EL2.TID5.
Affected Systems
All Linux ARM64 kernels that are compiled with CONFIG_ARM64_MTE set to n or use the arm64.nomte command line option are potentially affected. The advisory does not list specific kernel versions, so any ARM64 kernel built without MTE support is vulnerable. Systems that employ KVM for virtualization are the most likely to encounter the failure upon CPU state transitions.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not in the CISA KEV catalog, indicating a low probability of exploitation. However, the impact is severe: a single trigger will crash the host kernel and service. Exploitability requires a kernel with MTE disabled and the ability to force CPU re‑online events or influence KVM configuration, which typically limits the threat to privileged or local attackers.
OpenCVE Enrichment