« Volver al listado

CVE-2026-72278

Estado: RecibidaCrítica (9.3)—

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: nv: Re-translate VNCR before injecting abort

KVM faults in the VNCR page with FOLL_WRITE whenever the guest aborts for a write, similar to how a regular stage-2 mapping is handled. It is entirely possible that the guest reads from the VNCR before writing to it, in which case the PFN could only be read-only.

Invalidate the VNCR TLB and re-fetch the translation upon taking a VNCR abort, allowing the host mapping to be faulted in for write the second time around. Interestingly enough, this also satisfies the ordering requirements of FEAT_ETS2/3 between descriptor updates and MMU faults.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local del kernel Linux (AV:L, PR:N, UI:N) que afecta a KVM/arm64; permite escalada de privilegios mediante manipulación de VNCR. Impactos: ejecución de código y potencial denegación de servicio por el manejo incorrecto de traducciones de memoria.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72278",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.3,
          "attackVector": "LOCAL",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2a359e072596fcb2e9e85017a865e3618a2fe5b5",
              "lessThan": "ea7a76d7d614b5f82b4d0785f9af3550e860a71a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2a359e072596fcb2e9e85017a865e3618a2fe5b5",
              "lessThan": "0a5dd8cf4d58ea28da132c2097cd1c525302ac48",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2a359e072596fcb2e9e85017a865e3618a2fe5b5",
              "lessThan": "bb645aa0a4caeaf7f9cd32e9a948594d434c1a8f",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/arm64/kvm/nested.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/arm64/kvm/nested.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:57.927",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0a5dd8cf4d58ea28da132c2097cd1c525302ac48",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bb645aa0a4caeaf7f9cd32e9a948594d434c1a8f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ea7a76d7d614b5f82b4d0785f9af3550e860a71a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: nv: Re-translate VNCR before injecting abort\n\nKVM faults in the VNCR page with FOLL_WRITE whenever the guest aborts\nfor a write, similar to how a regular stage-2 mapping is handled. It is\nentirely possible that the guest reads from the VNCR before writing to\nit, in which case the PFN could only be read-only.\n\nInvalidate the VNCR TLB and re-fetch the translation upon taking a VNCR\nabort, allowing the host mapping to be faulted in for write the second\ntime around. Interestingly enough, this also satisfies the ordering\nrequirements of FEAT_ETS2/3 between descriptor updates and MMU faults."
    }
  ],
  "lastModified": "2026-08-17T06:18:30.363",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}