Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm): Guest-supplied array indices in the host's local-APIC emulation (an IPI destination id and
Impact
Guest-supplied array indices in the host's local-APIC emulation (an IPI destination id and a lowest-priority search index) were bounds-checked but never clamped, leaving a Spectre-v1 gadget that the guest controls. A tenant can train the bounds check and have the host speculatively read memory past those arrays, then recover it through a cache side channel - host kernel data disclosed into the VM.
Who can reach it
Guest-driven and unprivileged inside the VM: the tenant issues IPIs and APIC/MSR writes with out-of-range destination values from any vCPU. No host privilege, no device node, no VMM cooperation, and it works on both Intel and AMD hosts with in-kernel APIC emulation (the default).
What to do
Update to a stable kernel with the linked fix (no fixed release enumerated; take the branch carrying commit d51e381beed5). No practical interim control - moving APIC emulation to userspace is not a realistic production option.
References
Related entries
- Linux kernel (arch/x86/kvm): The I/O APIC's delayed EOI work was cancelled only after vCPUs were freed, so the workCVE-2026-74517 · Linux kernel (arch/x86/kvm)Critical
- Linux kernel (arch/x86/kvm): A guest that is in SMM and then triple-faults makes SVM take the SHUTDOWN intercept andCVE-2025-37957 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): An emulated MMIO write that straddles a page boundary onto a second MMIO page is splitCVE-2026-31588 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): When KVM failed to program the interrupt remapping table for irq bypass, it left aCVE-2026-72283 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A nested guest can put an out-of-range virtual-processor ID into an enlightened VMCS andCVE-2026-64247 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A guest that is not advertised long mode makes the host's SMM emulator walk 16CVE-2022-49883 · Linux kernel (arch/x86/kvm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.