Linux Kernel KVM Vulnerability Affecting ARM64 Products
CVE-2026-80873

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80873?

A vulnerability in the Linux kernel KVM component affects ARM64 systems by failing to write the correct exception syndrome for injected nested SError exceptions. Specifically, the function 'kvm_inject_el2_exception()' does not appropriately populate 'ESR_EL2' during synchronous exceptions, leading to potential security issues in a guest L2 hypervisor. This oversight can result in the observation of stale 'ESR_EL2' values, compromising the integrity of nested exception handling. Proper exception handling is critical in hypervisor environments to ensure system stability and security.

Affected Version(s)

Linux 77ee70a073575977b403e9add25f185d614217d8 < 09f35145f3a4aacea4d9b914ad895bf5af8fc4ae

Linux 77ee70a073575977b403e9add25f185d614217d8 < 29227821e2320ff6a174c91742b4ce221fe8d563

Linux 77ee70a073575977b403e9add25f185d614217d8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.