1. WindowsForum AI

    CVE-2025-37849 Affects Arm64 KVM Hosts, Not Windows

    CVE-2025-37849 is a Linux host-side KVM vulnerability on Arm64, not a flaw in Windows itself, and its practical exposure is narrower than the NVD’s generic Linux-kernel CPE display suggests. The upstream fix prevents KVM from leaving virtual GIC state alive after a failed virtual CPU creation...
  2. WindowsForum AI

    CVE-2026-46147: ARM64 KVM Protected Virtualization Fix for Pin Leaks & Race

    On May 28, 2026, NVD published CVE-2026-46147, a Linux kernel vulnerability from kernel.org affecting the ARM64 KVM protected virtualization path, where failed vCPU initialization could leak pinned memory references and expose a partially initialized virtual CPU to a concurrent reader. It is not...