CVE Database
/

CVE-2026-31553

Back to search

CVE-2026-31553

Published: Apr 24, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the descriptor address in __kvm_at_swap_desc() Using "(u64 __user *)hva + offset" to get the virtual addresses of S1/S2 descriptors looks really wrong, if offset is not zero. What we want to get for swapping is hva + offset, not hva + offset*8. ;-) Fix it.

VendorProductVersions

Linux

Linux

affected
f6927b41d57390c597a126063e2e518911976878 - < 4307e05e568782fc92eff651b09ee5dee88a058d
affected
f6927b41d57390c597a126063e2e518911976878 - < 0496acc42fb51eee040b5170cec05cec41385540

Linux

Linux

affected
6.19
unaffected
0 - < 6.19
unaffected
6.19.11 - <= 6.19.*
unaffected
7.0 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now