Bug 2525465 (CVE-2026-80699) - CVE-2026-80699 kernel: KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
Summary: CVE-2026-80699 kernel: KVM: arm64: vgic: Avoid double-deactivate of IRQs in t...
Keywords:
Status: NEW
Alias: CVE-2026-80699
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-28 07:46 UTC by OSIDB Bzimport
Modified: 2026-09-03 15:51 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-28 07:46:22 UTC
In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context

In the nested state, the physical interrupt has already been
deactivated through the HW bit in the LR. The extra deactivation
would be harmless but can hit an errata case on AmpereOne, so
avoid it here.

On AmpereOne, deactivating a physical interrupt through
ICC_DIR_EL1 or ICC_EOIR1_EL1 (depending on EOImode) which is not
active, but is the highest priority pending interrupt causes the
cpu to lose the interrupt pending state and also prevents the
delivery of future interrupts.


Note You need to log in before you can comment on or make changes to this bug.