SB20260406110 - Improper Initialization in Linux kernel hyp nvhe



SB20260406110 - Improper Initialization in Linux kernel hyp nvhe

Published: April 6, 2026

Security Bulletin ID SB20260406110
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Initialization (CVE-ID: CVE-2026-23425)

The vulnerability allows a local user to cause state corruption.

The vulnerability exists due to improper initialization in ID register initialization for non-protected pKVM guests when initializing the hypervisor kvm structure from the host state. A local user can create a non-protected VM to cause state corruption.

The issue affects non-protected arm64 pKVM guests because the ID register initialized flag can be copied without the underlying id_regs data being initialized, causing feature checks at EL2 to fail and some system registers to not be saved or restored during the world switch.


Remediation

Install update from vendor's website.