๐Ÿ” CVE Alert

CVE-2026-89912

UNKNOWN 0.0

KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save MAPC with V=0 drops ite->collection but leaves the ITE on the device's ITT list, and vgic_its_save_ite() dereferences it unconditionally. A guest that issues MAPD, MAPTI and then MAPC(V=0) therefore oopses the host when the VMM issues KVM_DEV_ARM_ITS_SAVE_TABLES to migrate it. That sequence is UNPREDICTABLE per the architecture, but KVM already handles the resulting state in the translate, MOVI and DISCARD paths. Save a zeroed entry, which vgic_its_restore_ite() reads back as invalid. Skipping the ITE instead would leave the ITT slot holding whatever is in guest memory, and restore rejects an entry naming a collection the restored collection table does not have.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
eff484e0298da5a4d18ca82f5454c557fd942af5 < 3d4c26b16a04a084fe0bde08ccdd8086570f8bbe eff484e0298da5a4d18ca82f5454c557fd942af5 < 36df368861d2664291298feeb37dfef43fcae670 eff484e0298da5a4d18ca82f5454c557fd942af5 < c6c156d931c33b92362383cf76f6d6e1291dcbfe
Linux / Linux
4.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3d4c26b16a04a084fe0bde08ccdd8086570f8bbe git.kernel.org: https://git.kernel.org/stable/c/36df368861d2664291298feeb37dfef43fcae670 git.kernel.org: https://git.kernel.org/stable/c/c6c156d931c33b92362383cf76f6d6e1291dcbfe