CVE-2026-80699

Source
https://cve.org/CVERecord?id=CVE-2026-80699
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80699.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80699
Downstream
Published
2026-08-28T06:53:03.430Z
Modified
2026-08-30T03:48:21.080502136Z
Summary
KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context

In the nested state, the physical interrupt has already been deactivated through the HW bit in the LR. The extra deactivation would be harmless but can hit an errata case on AmpereOne, so avoid it here.

On AmpereOne, deactivating a physical interrupt through ICCDIREL1 or ICCEOIR1EL1 (depending on EOImode) which is not active, but is the highest priority pending interrupt causes the cpu to lose the interrupt pending state and also prevents the delivery of future interrupts.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80699.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6dd333c8942b2e5bb5927af843b56ec2857db7c7
Fixed
f78f08b38a7f121c7d6b3e41002d9de7fd3c9189
Fixed
8a570b19b4b16a8a3b5ffa2b332bd5613110b2d8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80699.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80699.json"