From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-72284: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
Date: Sat, 15 Aug 2026 15:06:03 +0900 [thread overview]
Message-ID: <2026081559-CVE-2026-72284-8af0@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
Ignore KVM's internal "service pending PV EOI" request if the vCPU has
disabled PV EOIs since the request was made. Asserting that PV EOIs are
enabled can fail if reading guest memory in pv_eoi_get_user() fails, i.e.
if pv_eoi_test_and_clr_pending() bails early, *and* the vCPU also disables
PV EOIs.
kernel BUG at arch/x86/kvm/lapic.c:3338!
Oops: invalid opcode: 0000 [#1] SMP
CPU: 4 UID: 1000 PID: 890 Comm: pv_eoi_test Not tainted 7.0.0-d585aa5894d8-vm #337 PREEMPT
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
RIP: 0010:kvm_lapic_sync_from_vapic+0x12b/0x140 [kvm]
Call Trace:
<TASK>
kvm_arch_vcpu_ioctl_run+0x1075/0x1c30 [kvm]
kvm_vcpu_ioctl+0x2d5/0x980 [kvm]
__x64_sys_ioctl+0x8a/0xd0
do_syscall_64+0xb5/0xb40
entry_SYSCALL_64_after_hwframe+0x4b/0x53
</TASK>
Modules linked in: kvm_intel kvm irqbypass
---[ end trace 0000000000000000 ]---
The Linux kernel CVE team has assigned CVE-2026-72284 to this issue.
Affected and fixed versions
===========================
Issue introduced in 3.6 with commit ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb and fixed in 6.1.178 with commit 038b9ce6fafda1babd1e33d52cbc6039747a6d87
Issue introduced in 3.6 with commit ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb and fixed in 6.6.145 with commit 8e9f7a95279bf608cf4c331ed89612e28c04564f
Issue introduced in 3.6 with commit ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb and fixed in 6.12.97 with commit ebd7845ca0471d251a1cb48d84eb165aff5b7123
Issue introduced in 3.6 with commit ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb and fixed in 6.18.40 with commit 97542f15dc4cf6cd3fdc035e482dca54246ddf48
Issue introduced in 3.6 with commit ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb and fixed in 7.1.5 with commit 32bdca80aa81c2cb906f50a88b220ce1ecdc5e6e
Issue introduced in 3.6 with commit ae7a2a3fb6f8b784c2752863f4f1f20c656f76fb and fixed in 7.2-rc4 with commit 9285e4070df2c40585c3d7ec9571faa7a2b97e17
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-72284
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
arch/x86/kvm/lapic.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/038b9ce6fafda1babd1e33d52cbc6039747a6d87
https://git.kernel.org/stable/c/8e9f7a95279bf608cf4c331ed89612e28c04564f
https://git.kernel.org/stable/c/ebd7845ca0471d251a1cb48d84eb165aff5b7123
https://git.kernel.org/stable/c/97542f15dc4cf6cd3fdc035e482dca54246ddf48
https://git.kernel.org/stable/c/32bdca80aa81c2cb906f50a88b220ce1ecdc5e6e
https://git.kernel.org/stable/c/9285e4070df2c40585c3d7ec9571faa7a2b97e17
reply other threads:[~2026-08-15 6:20 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026081559-CVE-2026-72284-8af0@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.