CVE-2026-89727
Received Received - Intake

KVM: arm64 GICv2 Out-of-Range GICV_DIR INTID Handling

Vulnerability report for CVE-2026-89727, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID vgic_v2_deactivate() passes the INTID a guest wrote to GICV_DIR straight to vgic_get_vcpu_irq(), and treats a failed lookup as a "can't happen" condition with WARN_ON_ONCE(). The guest can make it happen at will, though: for any INTID outside of the implemented SGI, PPI and SPI ranges the lookup returns NULL, since GICv2 has no LPIs. A guest running with EOImode==1 writing such an INTID to GICV_DIR triggers the WARN, and panics hosts running with panic_on_warn. Drop the WARN and ignore failed lookups.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability in the KVM (Kernel-based Virtual Machine) subsystem for ARM64 systems using GICv2 interrupt controllers. A guest virtual machine can trigger a kernel warning by writing an invalid interrupt ID to a specific register (GICV_DIR). This causes the host system to panic if panic_on_warn is enabled, leading to a denial of service.

Detection Guidance

This vulnerability is specific to the Linux kernel's KVM implementation for arm64 systems. Detection requires checking kernel logs for WARN_ON_ONCE messages related to GICV_DIR INTID handling. Monitor dmesg or system logs for warnings about out-of-range GICV_DIR INTID values.

Impact Analysis

If you run virtual machines on a Linux host using KVM with ARM64 and GICv2, a malicious guest could crash your entire system by exploiting this flaw. This results in service disruption and potential data loss. Systems with panic_on_warn enabled are particularly vulnerable.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a Linux kernel issue related to KVM for arm64 systems, causing potential host crashes but not impacting data protection or privacy requirements.

Mitigation Strategies

Apply the latest kernel update provided by your Linux distribution to patch the KVM GICv2 issue. If immediate patching is not possible, disable KVM virtualization or restrict guest access to GICV_DIR writes until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89727. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart