CVE-2026-64288 | Linux Kernel up to 6.18.38/7.1.3 KVM arm64 VNCR pseudo-TLB kvm_invalidate_vncr_va null pointer dereference
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 6.18.38/7.1.3. This impacts the function kvm_invalidate_vncr_va of the component KVM arm64 VNCR pseudo-TLB. Such manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2026-64288. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More