Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-80665

 

Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-80665

Published: August 28, 2026


Vulnerability identifier: #VU146141
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80665
CWE-ID: CWE-703
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exception handling in KVM arm64 nested virtualization VNCR translation handling when processing VNCR aborts after kvm_translate_vncr() fails to resolve a PFN. A local user can trigger a translation failure involving a GFN outside of the memslots to cause a denial of service.

The issue occurs because late failures may be returned without the expected abort state being prepared for fault injection.


Affected software

Linux kernel
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)

How to mitigate CVE-2026-80665

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14

External References

Related Security Bulletins