CVE-2026-89727

Summary

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID

vgic_v2_deactivate() passes the INTID a guest wrote to GICV_DIR straight to vgic_get_vcpu_irq(), and treats a failed lookup as a "can't happen" condition with WARN_ON_ONCE().

The guest can make it happen at will, though: for any INTID outside of the implemented SGI, PPI and SPI ranges the lookup returns NULL, since GICv2 has no LPIs. A guest running with EOImode==1 writing such an INTID to GICV_DIR triggers the WARN, and panics hosts running with panic_on_warn.

Drop the WARN and ignore failed lookups.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux255de897e7fb918a34845167c572b5bf8e1d9d79 < 78b95c571d021391153a5ac7981e9e4d5cc856a3affected
LinuxLinux255de897e7fb918a34845167c572b5bf8e1d9d79 < c6d9c8ac6521d3049ec90ac58bebd23ed03ac496affected
LinuxLinux6.19affected
LinuxLinux0 < 6.19unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References