CVE-2026-64106

Summary

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits

Userspace can restore an ITS Device Table Entry whose Size field encodes more EventID bits than the virtual ITS supports. The live MAPD path rejects that state, but vgic_its_restore_dte() accepts it and stores the out-of-range value in dev->num_eventid_bits.

Reject restored DTEs with num_eventid_bits > VITS_TYPER_IDBITS before allocating the device. This mirrors the MAPD check and prevents the restored state from reaching vgic_its_restore_itt(), where the unchecked value can be converted into an oversized scan_its_table() range.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux57a9a117154c93539e33161dd318e6aeb8c04efa < 1716b7fea2ead941a0dfac06c4504a3437cdf00daffected
LinuxLinux57a9a117154c93539e33161dd318e6aeb8c04efa < dab9f93251b2c86a033de6098d0c73afddd55d4aaffected
LinuxLinux57a9a117154c93539e33161dd318e6aeb8c04efa < b94538186a3eae3763b8f96dacd610920a865aa7affected
LinuxLinux57a9a117154c93539e33161dd318e6aeb8c04efa < 0680f511926589206f81f57f76ce131d7741a316affected
LinuxLinux57a9a117154c93539e33161dd318e6aeb8c04efa < 8bcd15b690a390241179516af1b6ae49ebfd9d95affected
LinuxLinux57a9a117154c93539e33161dd318e6aeb8c04efa < 9ce754ed8e7ab4e3999767ce1505f85c449ccb07affected
LinuxLinux4.12affected
LinuxLinux0 < 4.12unaffected
LinuxLinux6.1.175 <= 6.1.*unaffected
LinuxLinux6.6.142 <= 6.6.*unaffected
LinuxLinux6.12.92 <= 6.12.*unaffected
LinuxLinux6.18.34 <= 6.18.*unaffected
LinuxLinux7.0.11 <= 7.0.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References