KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits

Summary

CVECVE-2026-64106
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-19 16:17:51 UTC
Updated2026-07-19 16:17:51 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an ITS Device Table Entry whose Size field encodes more EventID bits than the virtual ITS supports. The live MAPD path rejects that state, but vgic_its_restore_dte() accepts it and stores the out-of-range value in dev->num_eventid_bits. Reject restored DTEs with num_eventid_bits > VITS_TYPER_IDBITS before allocating the device. This mirrors the MAPD check and prevents the restored state from reaching vgic_its_restore_itt(), where the unchecked value can be converted into an oversized scan_its_table() range.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 57a9a117154c93539e33161dd318e6aeb8c04efa 1716b7fea2ead941a0dfac06c4504a3437cdf00d git Not specified
CNA Linux Linux affected 57a9a117154c93539e33161dd318e6aeb8c04efa dab9f93251b2c86a033de6098d0c73afddd55d4a git Not specified
CNA Linux Linux affected 57a9a117154c93539e33161dd318e6aeb8c04efa b94538186a3eae3763b8f96dacd610920a865aa7 git Not specified
CNA Linux Linux affected 57a9a117154c93539e33161dd318e6aeb8c04efa 0680f511926589206f81f57f76ce131d7741a316 git Not specified
CNA Linux Linux affected 57a9a117154c93539e33161dd318e6aeb8c04efa 8bcd15b690a390241179516af1b6ae49ebfd9d95 git Not specified
CNA Linux Linux affected 57a9a117154c93539e33161dd318e6aeb8c04efa 9ce754ed8e7ab4e3999767ce1505f85c449ccb07 git Not specified
CNA Linux Linux affected 4.12 Not specified
CNA Linux Linux unaffected 4.12 semver Not specified
CNA Linux Linux unaffected 6.1.175 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.142 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.92 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.34 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.11 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/dab9f93251b2c86a033de6098d0c73afddd55d4a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/0680f511926589206f81f57f76ce131d7741a316 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b94538186a3eae3763b8f96dacd610920a865aa7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1716b7fea2ead941a0dfac06c4504a3437cdf00d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/9ce754ed8e7ab4e3999767ce1505f85c449ccb07 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/8bcd15b690a390241179516af1b6ae49ebfd9d95 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report