In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
kvm_hyp_handle_mops() resets the single-step state machine as part of rewinding state for a MOPS exception by modifying vcpu_cpsr() and writing the result directly into hardware.
In the case of nested virtualization, vcpu_cpsr() is a synthetic value such that the rest of KVM can deal with vEL2 cleanly. That means the value requires translation before being written into hardware, which is unfortunately missing from the MOPS handler.
Fix it by directly modifying SPSR_EL2 and avoiding the synthetic state altogether, which will be resynchronized on the next 'full' exit back to KVM.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade python3-perf6.12Upgrade kernel-livepatch-6.12.100-125.179Upgrade kernel6.12-modules-extraUpgrade kernel6.12-debuginfo-common-aarch64Upgrade perf6.12-debuginfoUpgrade kernel6.12-tools-develUpgrade kernel6.12-develUpgrade python3-perf6.12-debuginfoUpgrade kernel6.12-toolsUpgrade kernel6.12-debuginfoUpgrade kernel6.12-modules-extra-commonUpgrade kernel6.12-debuginfo-common-x86_64Upgrade kernel6.12-tools-debuginfoUpgrade perf6.12Upgrade kernel6.12-headersUpgrade bpftool6.12-debuginfoUpgrade bpftool6.12Upgrade kernel6.12 | Aug 18, 2026 | Jul 27, 2026 |
| Debian | — | Upgrade linux-6.12Upgrade linux | Aug 2, 2026 | Aug 2, 2026 |
| Redhat_linux | — | No solution exists | Jul 30, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-nvidia-tegra-rtUpgrade linux-image-nvidia-tegra-6.8Upgrade linux-image-nvidia-tegra-rt-6.8Upgrade linux-image-nvidia-tegraUpgrade linux-image-6.8.0-1035-nvidia-tegra-rtUpgrade linux-image-6.8.0-1035-nvidia-tegraNo solution exists | Sep 21, 2026 | Sep 18, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 14, 2026 | Jul 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub