Out-of-bounds read in Linux kernel - CVE-2026-64287
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to an out-of-bounds access in flush_hyp_vcpu() and the vGIC list register save and restore logic when copying host-controlled vgic_v3 state into the pKVM hyp vCPU. A local privileged user can provide a crafted used_lrs value to trigger out-of-bounds access at EL2 to cause a denial of service.
The issue affects arm64 KVM with pKVM and involves host-to-EL2 state transfer.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64287
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/2c5e72b9fbf83fdfa724e9f1af0f418ccf8739b8
- https://git.kernel.org/stable/c/7fca3fcef81c713bc82a37bf741e0f28e6d04a6f
- https://git.kernel.org/stable/c/8cc8bbbfab14c22c5551d0dd19b208a44b141c76
- https://git.kernel.org/stable/c/9fa301d8298778dd799fa4dcf7a7f440715d146e
- https://git.kernel.org/stable/c/c646431865f4b1a5b14067233fa27b11e05e0d46