Improper control of a resource through its lifetime in Linux kernel - CVE-2026-64555

 

Improper control of a resource through its lifetime in Linux kernel - CVE-2026-64555

Published: July 28, 2026


Vulnerability identifier: #VU139812
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64555
CWE-ID: CWE-664
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause incorrect hypervisor state handling.

The vulnerability exists due to improper state management in kvm_hyp_handle_mops() when handling a MOPS exception during nested virtualization. A local user can trigger this code path to cause incorrect hypervisor state handling.

The issue affects arm64 KVM in nested virtualization scenarios.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-64555

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.100-1

External References

Related Security Bulletins