PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72277 Linux CVE debrief

The Linux kernel's KVM implementation for arm64 has a vulnerability related to how VNCR mappings are constructed. Specifically, KVM unconditionally uses cacheable memory attributes when constructing an L1 VNCR mapping, even if the underlying physical frame number isn't memory. This can cause issues, particularly if the endpoint doesn't support cacheable memory attributes, potentially leading to an SError on writeback. The solution involves rejecting anything that isn't memory. Affected product deployments should be verified, and owners assigned for follow-up. Official advisories or CVE records should be reviewed to validate affected scope, severity, and vendor guidance.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Users of KVM on arm64 systems, Linux kernel maintainers, administrators responsible for virtualization infrastructure, and security teams should verify their configurations and kernel versions. Affected operators and platforms should review compensating controls for exposed systems while remediation is scheduled and verified. Vulnerability management and security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory and monitoring teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. System administrators should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Security teams should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. System administrators and security teams should work together to assign owners for follow-up and verify affected scope and severity. Security teams should also review compensating controls for exposed systems while remediation is scheduled and verified. System administrators and security teams should also verify affected product deployments exist in managed environments and assign an owner for follow-up. Security teams should also review relevant monitoring, detection, and logs for exposed assets that need extra review. System administrators and security teams should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Security teams should also track exceptions, retest remediated assets, and close the item only after evidence is documented. System administrators and security teams should also review compensating controls for exposed systems while remediation is scheduled and verified. System administrators should also check relevant monitoring, detection, and logs for exposed assets that need extra review. Security teams should also assign owners for follow-up and verify affected scope and severity. System administrators and security teams should also work together to verify affected product deployments exist in managed environments and assign an

Technical summary

The Linux kernel's KVM implementation for arm64 has a vulnerability related to how VNCR mappings are constructed. Specifically, KVM unconditionally uses cacheable memory attributes when constructing an L1 VNCR mapping, even if the underlying physical frame number isn't memory. This can cause issues, particularly if the endpoint doesn't support cacheable memory attributes, potentially leading to an SError on writeback. The solution involves rejecting anything that isn't memory.

Defensive priority

This CVE is related to the Linux kernel and a potential vulnerability in KVM for arm64. Users of KVM on arm64 systems should verify their configurations and kernel versions.

Recommended defensive actions

  • Verify kernel versions and KVM configurations on arm64 systems.
  • Check for and apply any available patches or updates from the Linux kernel maintainers.
  • Monitor system logs for SError occurrences that could be related to this issue.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The CVE is related to a vulnerability in the Linux kernel's KVM implementation for arm64, specifically with how VNCR mappings are constructed and memory attributes are handled. The issue arises when KVM uses cacheable memory attributes even if the underlying physical frame number isn't memory, which could lead to errors like SError on writeback. The fix involves rejecting anything that isn't memory.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72277 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72277

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72277 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72277

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4bd7dbe0b2243e6aa735cae4d5e1ff988b30b2a6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bc00e0e376ee3572f5d26c174473abef1e35decc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d5436e18e4fc2886ac306304d884ea3b92e1edbf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.