CVE-2026-80699
Last modified
CVE-2026-80699 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context In the nested state, the physical interrupt has already been deactivated through the HW bit in the LR. The extra deactivation would be harmless but can hit an errata case on AmpereOne, so avoid it here. On AmpereOne, deactivating a physical interrupt through ICC_DIR_EL1 or ICC_EOIR1_EL1 (depending on EOImode) which is not active, but is the highest priority pending interrupt causes the cpu to lose the interrupt pending state and also prevents the delivery of future interrupts..
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context In the nested state, the physical interrupt has already been deactivated through the HW bit in the LR. The extra deactivation would be harmless but can hit an errata case on AmpereOne, so avoid it here. On AmpereOne, deactivating a physical interrupt through ICC_DIR_EL1 or ICC_EOIR1_EL1 (depending on EOImode) which is not active, but is the highest priority pending interrupt causes the cpu to lose the interrupt pending state and also prevents the delivery of future interrupts.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 6dd333c8942b2e5bb5927af843b56ec2857db7c7, < f78f08b38a7f121c7d6b3e41002d9de7fd3c9189; >= 6dd333c8942b2e5bb5927af843b56ec2857db7c7, < 8a570b19b4b16a8a3b5ffa2b332bd5613110b2d8 |
| Linux | Linux | 6.19 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80699?
How severe is CVE-2026-80699?
How do I fix CVE-2026-80699?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80693In the Linux kernel, the following vulnerability has been re…9.3
- CVE-2026-80694In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-80695In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80696In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80697In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80698In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8070Incorrect permission assignment for a critical resource in A…7.3
- CVE-2026-80700In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80701In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80702In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80703In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80704In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-80699?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
