Improper control of a resource through its lifetime in Linux kernel - CVE-2026-64555
Published: July 28, 2026
Vulnerability details
The vulnerability allows a local user to cause incorrect hypervisor state handling.
The vulnerability exists due to improper state management in kvm_hyp_handle_mops() when handling a MOPS exception during nested virtualization. A local user can trigger this code path to cause incorrect hypervisor state handling.
The issue affects arm64 KVM in nested virtualization scenarios.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64555
linux (Debian package) - update to 6.12.100-1