CVE-2026-64106

Source
https://cve.org/CVERecord?id=CVE-2026-64106
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64106.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64106
Downstream
Published
2026-07-19T15:40:09.344Z
Modified
2026-07-21T03:47:53.874254584Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H CVSS Calculator
Summary
KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: vgic-its: Reject restored DTE with out-of-range numeventidbits

Userspace can restore an ITS Device Table Entry whose Size field encodes more EventID bits than the virtual ITS supports. The live MAPD path rejects that state, but vgicitsrestoredte() accepts it and stores the out-of-range value in dev->numeventid_bits.

Reject restored DTEs with numeventidbits > VITSTYPERIDBITS before allocating the device. This mirrors the MAPD check and prevents the restored state from reaching vgicitsrestoreitt(), where the unchecked value can be converted into an oversized scanits_table() range.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64106.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
57a9a117154c93539e33161dd318e6aeb8c04efa
Fixed
1716b7fea2ead941a0dfac06c4504a3437cdf00d
Fixed
dab9f93251b2c86a033de6098d0c73afddd55d4a
Fixed
b94538186a3eae3763b8f96dacd610920a865aa7
Fixed
0680f511926589206f81f57f76ce131d7741a316
Fixed
8bcd15b690a390241179516af1b6ae49ebfd9d95
Fixed
9ce754ed8e7ab4e3999767ce1505f85c449ccb07

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64106.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.142
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64106.json"