Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm): A guest that is not advertised long mode makes the host's SMM emulator walk 16
Impact
A guest that is not advertised long mode makes the host's SMM emulator walk 16 general-purpose register slots through a 32-bit SMRAM image, running off the end of the host-side buffer. The overrun happens in host kernel memory while emulating SMI entry and RSM, so a tenant VM gets an out-of-bounds host kernel read/write instead of a contained guest fault.
Who can reach it
Fully guest-driven on a 64-bit host: a tenant running a VM whose CPUID lacks X86_FEATURE_LM raises an SMI (a guest can direct one at itself through the emulated local APIC) and executes RSM. No VMM cooperation, no ioctl, no device node inside the container or guest is required.
What to do
Boot a kernel carrying the linked stable fix; the record enumerates no fixed release, so pick the stable point release that contains commit a7ebfbea0f52. Interim control: always expose long mode (X86_FEATURE_LM) in tenant guest CPUID so the 32-bit SMRAM path is never taken, since SMM emulation itself cannot be turned off per VM.
References
Related entries
- Linux kernel (arch/x86/kvm): A guest that disables paravirtual EOI while KVM still has a pending PV-EOI request, andCVE-2026-72284 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A failed RSM leaves the vCPU's SMM flag and the MMU role out of sync, so KVM resolves aCVE-2021-47230 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): The guard against accessing bytes 4-15 of an emulated APIC register was dropped, andCVE-2021-47255 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): A guest using its APIC timer in periodic mode can leave KVM programming an already-expiredCVE-2025-71104 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): Guest-supplied array indices in the host's local-APIC emulation (an IPI destination id andCVE-2025-39823 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): The I/O APIC's delayed EOI work was cancelled only after vCPUs were freed, so the workCVE-2026-74517 · Linux kernel (arch/x86/kvm)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.