Hi, Please apply commits 4eaed6aa2c62 ("arm64/kvm: consistently handle host HCR_EL2 flags") b3669b1e1c09 ("arm64: Don't trap host pointer auth use to EL2") to the 4.19.y (and 4.20.y) stable kernels. The patches prevent userspace from entering KVM directly on newer ARM CPUs. I'll also send backports for the 4.4.y, 4.9.y, and 4.14.y stable kernels in reply to this email. Thanks, Kristina