cbcvebase.
CVE-2026-23085
published 2026-02-04

CVE-2026-23085: In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Avoid truncating memory addresses On 32-bit machines with…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Avoid truncating memory addresses On 32-bit machines with CONFIG_ARM_LPAE, it is possible for lowmem allocations to be backed by addresses physical memory above the 32-bit address limit, as found while experimenting with larger VMSPLIT configurations. This caused the qemu virt model to crash in the GICv3 driver, which allocates the 'itt' object using GFP_KERNEL. Since all memory below the 4GB physical address limit is in ZONE_DMA in this configuration, kmalloc() defaults to higher addresses for ZONE_NORMAL, and the ITS driver stores the physical address in a 32-bit 'unsigned long' variable. Change the itt_addr variable to the correct phys_addr_t type instead, along with all other variables in this driver that hold a physical address. The gicv5 driver correctly uses u64 variables, while all other irqchip drivers don't call virt_to_phys or similar interfaces. It's expected that other device drivers have similar issues, but fixing this one is sufficient for booting a virtio based guest.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e < e332b3b69e5b3acf07204a4b185071bab15c2b88e332b3b69e5b3acf07204a4b185071bab15c2b88
linuxlinux>= cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e < e2f9c751f73a2d5bb62d94ab030aec118a811f27e2f9c751f73a2d5bb62d94ab030aec118a811f27
linuxlinux>= cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e < 85215d633983233809f7d4dad163b953331b823885215d633983233809f7d4dad163b953331b8238
linuxlinux>= cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e < 1b323391560354d8c515de8658b057a1daa82adb1b323391560354d8c515de8658b057a1daa82adb
linuxlinux>= cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e < 084ba3b99f2dfd991ce7e84fb17117319ec3cd9f084ba3b99f2dfd991ce7e84fb17117319ec3cd9f
linuxlinux>= cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e < 03faa61eb4b9ca9aa09bd91d4c3773d8e7b1ac9803faa61eb4b9ca9aa09bd91d4c3773d8e7b1ac98
linuxlinux>= cc2d3216f53c9fff0030eb71cacc4ce5f39d1d7e < 8d76a7d89c12d08382b66e2f21f20d0627d148598d76a7d89c12d08382b66e2f21f20d0627d14859
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 3.19 < 5.10.2495.10.249
linuxlinux_kernel>= 5.11 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13 < 6.18.86.18.8
linuxlinux_kernel>= 6.2 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7 < 6.12.686.12.68
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.