CVE-2026-64172
7.1Linux · Kernel
A hardware erratum handling flaw in the Linux kernel KVM SVM subsystem on Hygon Family 18h processors allows local denial of service via hung virtual CPUs.
Executive summary
A hardware erratum handling flaw in the Linux kernel KVM SVM subsystem on Hygon Family 18h processors can lead to guest execution hangs and denial of service.
Vulnerability
This is a kernel virtualization flaw involving improper handling of CPU erratum #1235 during AVIC IPI virtualization, requiring local execution with no privileges and no user interaction.
Business impact
A successful exploitation of this vulnerability results in hung virtual CPUs and unbounded delays in guest execution, causing critical service disruption and system instability for virtualized environments. While the CVSS score of 7.1 places this in the high severity range due to high availability impact, the attack vector is restricted to local execution context, limiting remote exposure.
Remediation
Immediate Action: Update the Linux kernel to version 6.18.34, 7.0.11, or later where the erratum workaround is applied.
Proactive Monitoring: Monitor hypervisor logs and guest virtual machine status for unexpected performance degradation, unresponsiveness, or vCPU lockups.
Compensating Controls: Restrict local shell access and ensure strict least privilege principles on virtualization hosts to prevent unauthorized local code execution.
Exploitation status
Public Exploit Available: No (no public exploit or weaponized module currently identified in available telemetry).
Analyst recommendation
System administrators managing virtualized environments on Hygon Family 18h or related AMD-derived processors must treat this advisory with high urgency. Applying the provided kernel updates immediately is essential to prevent hypervisor instability and potential denial of service conditions affecting guest workloads.