Answer in brief
CVE-2026-72278 records a Unknown severity vulnerability in KVM: arm64: nv: Re-translate VNCR before injecting abort. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2a359e072596fcb2e9e85017a865e3618a2fe5b5 <ea7a76d7d614b5f82b4d0785f9af3550e860a71a || >=2a359e072596fcb2e9e85017a865e3618a2fe5b5 <0a5dd8cf4d58ea28da132c2097cd1c525302ac48 || >=2a359e072596fcb2e9e85017a865e3618a2fe5b5 <bb645aa0a4caeaf7f9cd32e9a948594d434c1a8f | ea7a76d7d614b5f82b4d0785f9af3550e860a71a, 0a5dd8cf4d58ea28da132c2097cd1c525302ac48, bb645aa0a4caeaf7f9cd32e9a948594d434c1a8f |
| Linux/Linuxgeneric | 6.16 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Re-translate VNCR before injecting abort KVM faults in the VNCR page with FOLL_WRITE whenever the guest aborts for a write, similar to how a regular stage-2 mapping is handled. It is entirely possible that the guest reads from the VNCR before writing to it, in which case the PFN could only be read-only. Invalidate the VNCR TLB and re-fetch the translation upon taking a VNCR abort, allowing the host mapping to be faulted in for write the second time around. Interestingly enough, this also satisfies the ordering requirements of FEAT_ETS2/3 between descriptor updates and MMU faults.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-72278 records a Unknown severity vulnerability in KVM: arm64: nv: Re-translate VNCR before injecting abort. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2a359e072596fcb2e9e85017a865e3618a2fe5b5 <ea7a76d7d614b5f82b4d0785f9af3550e860a71a || >=2a359e072596fcb2e9e85017a865e3618a2fe5b5 <0a5dd8cf4d58ea28da132c2097cd1c525302ac48 || >=2a359e072596fcb2e9e85017a865e3618a2fe5b5 <bb645aa0a4caeaf7f9cd32e9a948594d434c1a8f | ea7a76d7d614b5f82b4d0785f9af3550e860a71a, 0a5dd8cf4d58ea28da132c2097cd1c525302ac48, bb645aa0a4caeaf7f9cd32e9a948594d434c1a8f |
| Linux/Linuxgeneric | 6.16 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Re-translate VNCR before injecting abort KVM faults in the VNCR page with FOLL_WRITE whenever the guest aborts for a write, similar to how a regular stage-2 mapping is handled. It is entirely possible that the guest reads from the VNCR before writing to it, in which case the PFN could only be read-only. Invalidate the VNCR TLB and re-fetch the translation upon taking a VNCR abort, allowing the host mapping to be faulted in for write the second time around. Interestingly enough, this also satisfies the ordering requirements of FEAT_ETS2/3 between descriptor updates and MMU faults.
Quoted source text, attributed separately from HOL analysis.