What is CVE-2026-64288?
CVE-2026-64288 is a vulnerability in the Linux kernel's KVM arm64 nested virtualization (NV) where a race condition can lead to a NULL pointer dereference of the VNCR pseudo-TLB. This occurs when TLB invalidation races against a vCPU that hasn't been onlined yet, potentially causing a system crash. Affected systems should apply the kernel patch.
Azərbaycanca: CVE-2026-64288 Linux kernel-in KVM arm64 nüvəsində (NV) aşkarlanan boşluqdur: VNCR pseudo-TLB-nin NULL göstəricisinə müraciət (dereference) edilərək sistem çöküşünə səbəb ola bilər. Bu, hələ onlayn olmayan vcpu ilə TLB təmizləmə əməliyyatı yarışdıqda (race condition) baş verir. Təsirə məruz qalan sistemlərdə kernel yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-476; shared vendor: Linux
FAQ2
What software is affected by CVE-2026-64288?
This vulnerability affects the Linux kernel's KVM arm64 subsystem, specifically the nested virtualization (NV) functionality.
What could exploitation of CVE-2026-64288 lead to?
Exploitation of this vulnerability can result in a NULL pointer dereference, potentially causing a system crash.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.