PT-2026-47753 · Linux+2 · Linux Kernel+2
CVSS v3.1
9.3
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 13031fb6b835
Description
A critical guest-to-host escape flaw, dubbed ITScape, exists in the Kernel-based Virtual Machine (KVM) for ARM64, specifically within the vGIC-ITS (Interrupt Translation Service) emulation component. The issue is caused by a race condition in the
vgic its invalidate cache() function, where multiple concurrent operations incorrectly drop the translation cache's reference to an entry more than once. This leads to a double-use-after-free condition, allowing an attacker in a guest operating system to execute arbitrary code with root privileges directly within the host kernel. This vulnerability specifically threatens multi-tenant ARM64 cloud environments where guest-host isolation is critical. The flaw is limited to ARM64 architectures and does not affect x86 systems.Recommendations
Update the Linux kernel to version 13031fb6b835 or later to resolve the race condition in the
vgic its invalidate cache() function.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Rocky Linux