๐Ÿ” CVE Alert

CVE-2026-64288

UNKNOWN 0.0

KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB VNCR TLB invalidation occurs from MMU notifiers or TLBI instructions, and either can race against a vcpu not being onlined yet (no pseudo-TLB allocated). Similarly, the TLB might be invalid, and the invalidation should be skipped in this case. Both kvm_invalidate_vncr_ipa() and kvm_invalidate_vncr_va() are expected to perform the same checks, except that the latter doesn't check for the allocation and blindly dereferences the pointer. Solve this by introducing a new iterator built on top of the usual kvm_for_each_vcpu() that checks for both of the above conditions, and convert the two users to it.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929 < 7c73a269a880b1399baacfb9d521415e6ef7ecc2 4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929 < 5fd30133af864a1de0a0bd87d3fe3cf23205fbc7 4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929 < 4be6cbeb93d26994bd1827ddbce391e3c4395c8f
Linux / Linux
6.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/7c73a269a880b1399baacfb9d521415e6ef7ecc2 git.kernel.org: https://git.kernel.org/stable/c/5fd30133af864a1de0a0bd87d3fe3cf23205fbc7 git.kernel.org: https://git.kernel.org/stable/c/4be6cbeb93d26994bd1827ddbce391e3c4395c8f