What is CVE-2026-64287?
This vulnerability in the Linux kernel's KVM arm64 subsystem arises from insufficient bounds checking of the used_lrs value when flushing the pKVM hyp vCPU, potentially allowing memory corruption during vGIC state copy. Affected systems using pKVM should apply kernel updates to mitigate the risk.
Azərbaycanca: Linux kernel-də KVM arm64 alt sistemində aşkar edilmiş bu boşluq pKVM hip vCPU-nun flush əməliyyatı zamanı used_lrs dəyərinin sərhədlərinin yoxlanılmaması ilə bağlıdır. Bu, zərərli istifadəçiyə host vGIC vəziyyətini kopyalayarkən yaddaş pozuntusuna səbəb olmaq imkanı verə bilər. Təsirə məruz qalan sistemlərdə kernelin yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which subsystem of the Linux kernel was the CVE-2026-64287 vulnerability discovered?
This vulnerability was discovered in the KVM arm64 subsystem of the Linux kernel.
During which operation could the CVE-2026-64287 vulnerability cause memory corruption?
This vulnerability could cause memory corruption during the pKVM hyp vCPU flush operation when copying the vGIC state.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.