« Volver al listado

CVE-2026-89727

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID

vgic_v2_deactivate() passes the INTID a guest wrote to GICV_DIR straight to vgic_get_vcpu_irq(), and treats a failed lookup as a "can't happen" condition with WARN_ON_ONCE().

The guest can make it happen at will, though: for any INTID outside of the implemented SGI, PPI and SPI ranges the lookup returns NULL, since GICv2 has no LPIs. A guest running with EOImode==1 writing such an INTID to GICV_DIR triggers the WARN, and panics hosts running with panic_on_warn.

Drop the WARN and ignore failed lookups.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89727",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "255de897e7fb918a34845167c572b5bf8e1d9d79",
              "lessThan": "78b95c571d021391153a5ac7981e9e4d5cc856a3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "255de897e7fb918a34845167c572b5bf8e1d9d79",
              "lessThan": "c6d9c8ac6521d3049ec90ac58bebd23ed03ac496",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/arm64/kvm/vgic/vgic-v2.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/arm64/kvm/vgic/vgic-v2.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:20:03.027",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/78b95c571d021391153a5ac7981e9e4d5cc856a3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c6d9c8ac6521d3049ec90ac58bebd23ed03ac496",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID\n\nvgic_v2_deactivate() passes the INTID a guest wrote to GICV_DIR straight\nto vgic_get_vcpu_irq(), and treats a failed lookup as a \"can't happen\"\ncondition with WARN_ON_ONCE().\n\nThe guest can make it happen at will, though: for any INTID outside of\nthe implemented SGI, PPI and SPI ranges the lookup returns NULL, since\nGICv2 has no LPIs. A guest running with EOImode==1 writing such an INTID\nto GICV_DIR triggers the WARN, and panics hosts running with\npanic_on_warn.\n\nDrop the WARN and ignore failed lookups."
    }
  ],
  "lastModified": "2026-09-11T20:20:03.027",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}