Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x8qc-pvh3-2vf6

Опубликовано: 15 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.3

Описание

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory

When constructing an L1 VNCR mapping, KVM unconditionally uses cacheable memory attributes, even if the underlying PFN isn't memory. This gets particularly hairy if the endpoint doesn't support cacheable memory attributes, potentially throwing an SError on writeback...

While KVM does permit cacheable memory attributes on certain PFNMAP VMAs, kvm_translate_vncr() isn't currently grabbing the VMA. So do the simpler thing for now and just reject everything that isn't memory.

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory

When constructing an L1 VNCR mapping, KVM unconditionally uses cacheable memory attributes, even if the underlying PFN isn't memory. This gets particularly hairy if the endpoint doesn't support cacheable memory attributes, potentially throwing an SError on writeback...

While KVM does permit cacheable memory attributes on certain PFNMAP VMAs, kvm_translate_vncr() isn't currently grabbing the VMA. So do the simpler thing for now and just reject everything that isn't memory.

EPSS

Процентиль: 11%
0.00206
Низкий

9.3 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.3
ubuntu
2 дня назад

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory When constructing an L1 VNCR mapping, KVM unconditionally uses cacheable memory attributes, even if the underlying PFN isn't memory. This gets particularly hairy if the endpoint doesn't support cacheable memory attributes, potentially throwing an SError on writeback... While KVM does permit cacheable memory attributes on certain PFNMAP VMAs, kvm_translate_vncr() isn't currently grabbing the VMA. So do the simpler thing for now and just reject everything that isn't memory.

CVSS3: 5.5
redhat
4 дня назад

A flaw was found in the Linux kernel's KVM (Kernel-based Virtual Machine) for ARM64 systems. When KVM constructs an L1 VNCR (Virtual Nested Control Register) mapping, it incorrectly applies cacheable memory attributes even when the underlying physical memory is not normal memory. This can lead to a system error (SError) during writeback operations, potentially causing system instability or a denial of service.

CVSS3: 9.3
nvd
4 дня назад

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory When constructing an L1 VNCR mapping, KVM unconditionally uses cacheable memory attributes, even if the underlying PFN isn't memory. This gets particularly hairy if the endpoint doesn't support cacheable memory attributes, potentially throwing an SError on writeback... While KVM does permit cacheable memory attributes on certain PFNMAP VMAs, kvm_translate_vncr() isn't currently grabbing the VMA. So do the simpler thing for now and just reject everything that isn't memory.

CVSS3: 9.3
debian
4 дня назад

In the Linux kernel, the following vulnerability has been resolved: K ...

EPSS

Процентиль: 11%
0.00206
Низкий

9.3 Critical

CVSS3