CVE-2026-23085
Published: Feb 4, 2026
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Avoid truncating memory addresses On 32-bit machines with CONFIG_ARM_LPAE, it is possible for lowmem allocations to be backed by addresses physical memory above the 32-bit address limit, as found while experimenting with larger VMSPLIT configurations. This caused the qemu virt model to crash in the GICv3 driver, which allocates the 'itt' object using GFP_KERNEL. Since all memory below the 4GB physical address limit is in ZONE_DMA in this configuration, kmalloc() defaults to higher addresses for ZONE_NORMAL, and the ITS driver stores the physical address in a 32-bit 'unsigned long' variable. Change the itt_addr variable to the correct phys_addr_t type instead, along with all other variables in this driver that hold a physical address. The gicv5 driver correctly uses u64 variables, while all other irqchip drivers don't call virt_to_phys or similar interfaces. It's expected that other device drivers have similar issues, but fixing this one is sufficient for booting a virtio based guest.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e - < e332b3b69e5b3acf07204a4b185071bab15c2b88affected cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e - < e2f9c751f73a2d5bb62d94ab030aec118a811f27affected cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e - < 85215d633983233809f7d4dad163b953331b8238affected cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e - < 1b323391560354d8c515de8658b057a1daa82adbaffected cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e - < 084ba3b99f2dfd991ce7e84fb17117319ec3cd9f+2 more versions |
Linux | Linux | affected 3.19unaffected 0 - < 3.19unaffected 5.10.249 - <= 5.10.*unaffected 5.15.199 - <= 5.15.*unaffected 6.1.162 - <= 6.1.*+4 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now