Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm): The guard against accessing bytes 4-15 of an emulated APIC register was dropped, and
Impact
The guard against accessing bytes 4-15 of an emulated APIC register was dropped, and reading those offsets leaks host kernel stack contents straight back to the guest. A tenant VM gets a repeatable read primitive into host kernel memory - useful for defeating KASLR and for harvesting whatever else sits on that stack.
Who can reach it
Issued from inside the guest with no privileges beyond guest ring 0: read an emulated local-APIC register at a misaligned offset. Applies to guests running with the in-kernel LAPIC and without APIC virtualization handling the access.
What to do
Update to a kernel with the referenced stable commits (no fixed release string published - match by commit). There is no practical interim control short of patching; the LAPIC is not something you can take away from a guest.
References
Related entries
- Linux kernel (arch/x86/kvm): A guest using its APIC timer in periodic mode can leave KVM programming an already-expiredCVE-2025-71104 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): Guest-supplied array indices in the host's local-APIC emulation (an IPI destination id andCVE-2025-39823 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): The I/O APIC's delayed EOI work was cancelled only after vCPUs were freed, so the workCVE-2026-74517 · Linux kernel (arch/x86/kvm)Critical
- Linux kernel (arch/x86/kvm): A guest that is in SMM and then triple-faults makes SVM take the SHUTDOWN intercept andCVE-2025-37957 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): An emulated MMIO write that straddles a page boundary onto a second MMIO page is splitCVE-2026-31588 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): When KVM failed to program the interrupt remapping table for irq bypass, it left aCVE-2026-72283 · Linux kernel (arch/x86/kvm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.