Reachable assertion in Linux kernel - CVE-2026-89727
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a reachable assertion in vgic_v2_deactivate() in the KVM arm64 GICv2 virtual interrupt controller when a guest running with EOImode==1 writes an out-of-range INTID to GICV_DIR. A local user can supply an out-of-range INTID to GICV_DIR to cause a denial of service.
The host panics only when panic_on_warn is enabled.