CVE-2026-80699 is a vulnerability in Linux Kernel
Published on August 28, 2026
KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
In the nested state, the physical interrupt has already been
deactivated through the HW bit in the LR. The extra deactivation
would be harmless but can hit an errata case on AmpereOne, so
avoid it here.
On AmpereOne, deactivating a physical interrupt through
ICC_DIR_EL1 or ICC_EOIR1_EL1 (depending on EOImode) which is not
active, but is the highest priority pending interrupt causes the
cpu to lose the interrupt pending state and also prevents the
delivery of future interrupts.
Products Associated with CVE-2026-80699
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 6dd333c8942b2e5bb5927af843b56ec2857db7c7 and below f78f08b38a7f121c7d6b3e41002d9de7fd3c9189 is affected.
- Version 6dd333c8942b2e5bb5927af843b56ec2857db7c7 and below 8a570b19b4b16a8a3b5ffa2b332bd5613110b2d8 is affected.
- Version 6.19 is affected.
- Before 6.19 is unaffected.
- Version 7.1.8, <= 7.1.* is unaffected.
- Version 7.2, <= * is unaffected.