CVE-2026-64287
ARM64 KVM vgic LR bounds bug allows guest access to EL2 registers
Is CVE-2026-64287 being exploited?
Not confirmed. CVE-2026-64287 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.18% probability of exploitation in the next 30 days.
How severe is CVE-2026-64287?
CVE-2026-64287 is rated High with a CVSS score of 8.2. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64287?
Yes. A fix has been recorded for CVE-2026-64287. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64287 affect?
CVE-2026-64287 affects Linux kernel KVM on arm64 (pKVM/hyp), ARM-based cloud hosts (e.g., Graviton/Ampere), Hypervisors/hosts running affected Linux kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64287?
Apply Linux kernel security updates and reboot affected hypervisors immediately
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Guest can trigger out-of-bounds vgic LR access at EL2, enabling guest-to-hypervisor privilege escalation or possible hypervisor code execution.
Immediate action required
- affected>= be66e67f175096f283c9d5614c4991fc9e7ed975 and < 2c5e72b9fbf83fdfa724e9f1af0f418ccf8739b8
- affected>= be66e67f175096f283c9d5614c4991fc9e7ed975 and < 9fa301d8298778dd799fa4dcf7a7f440715d146e
- affected>= be66e67f175096f283c9d5614c4991fc9e7ed975 and < c646431865f4b1a5b14067233fa27b11e05e0d46
- affected>= be66e67f175096f283c9d5614c4991fc9e7ed975 and < 7fca3fcef81c713bc82a37bf741e0f28e6d04a6f
- affected>= be66e67f175096f283c9d5614c4991fc9e7ed975 and < 8cc8bbbfab14c22c5551d0dd19b208a44b141c76
- affected6.2
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.