PT-2026-47753 · Linux+2 · Linux Kernel+2

·

CVE-2026-46316

·

Published

2026-06-01

·

Updated

2026-07-24

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 13031fb6b835
Description A critical guest-to-host escape flaw, dubbed ITScape, exists in the Kernel-based Virtual Machine (KVM) for ARM64, specifically within the vGIC-ITS (Interrupt Translation Service) emulation component. The issue is caused by a race condition in the vgic its invalidate cache() function, where multiple concurrent operations incorrectly drop the translation cache's reference to an entry more than once. This leads to a double-use-after-free condition, allowing an attacker in a guest operating system to execute arbitrary code with root privileges directly within the host kernel. This vulnerability specifically threatens multi-tenant ARM64 cloud environments where guest-host isolation is critical. The flaw is limited to ARM64 architectures and does not affect x86 systems.
Recommendations Update the Linux kernel to version 13031fb6b835 or later to resolve the race condition in the vgic its invalidate cache() function.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:30129
ALSA-2026:30848
ALSA-2026:34911
ALSA-2026:36018
BDU:2026-08088
CVE-2026-46316
OPENSUSE-SU-2026:11014-1
OPENSUSE-SU-2026:20965-1
RHSA-2026:34911
RHSA-2026:39371
SUSE-SU-2026:22099-1
SUSE-SU-2026:22112-1
SUSE-SU-2026:22117-1
SUSE-SU-2026:22127-1
USN-8488-1
USN-8488-2
USN-8489-1
USN-8490-1
USN-8490-2
USN-8491-1
USN-8507-1
USN-8508-1
USN-8545-1
USN-8546-1
USN-8569-1
USN-8603-1
USN-8604-1
USN-8605-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux