PT-2026-30039 · Linux+2 · Linux Kernel+2

Published

2026-04-03

·

Updated

2026-04-20

·

CVE-2026-23425

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue in KVM for arm64 systems related to the initialization of ID registers for non-protected pKVM guests. The hypervisor incorrectly copies the KVM ARCH FLAG ID REGS INITIALIZED flag from the host without initializing the underlying id regs data. This causes feature detection checks at EL2 to fail, impacting logic that relies on feature detection, such as ctxt has tcrx() for TCR2 EL1 support. As a result, system registers like TCR2 EL1, PIR EL1, and POR EL1 may not be saved or restored during world switches, potentially leading to state corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-23425
OPENSUSE-SU-2026:20572-1
SUSE-SU-2026:21237-1

Affected Products

Kvm
Linux Kernel
Arm64