Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm): A guest using its APIC timer in periodic mode can leave KVM programming an already-expired
Impact
A guest using its APIC timer in periodic mode can leave KVM programming an already-expired hypervisor timer over and over, producing a practically unbounded storm of host hrtimer interrupts. The upstream fix states this can hard-lock the host - a whole-node outage that takes every other tenant on the box down with it, so the impact is DoS rather than escape.
Who can reach it
The guest side is trivial and unprivileged: any tenant programs a periodic LAPIC timer. The trigger is a long gap in vCPU execution - VM pause/suspend, a live-migration blackout window, or severe host oversubscription - after which the expiration delta goes negative and overflows what the VMX preemption timer can encode. Intel hosts using the hypervisor timer, which is the default.
What to do
Update to a stable kernel carrying the linked fix; the record's version list does not name a usable fixed release, so track the branch containing commit 786ed625c125. Interim controls: avoid long pause/suspend of running tenant VMs and, at a performance cost, disable the VMX preemption timer for KVM (kvm_intel.preemption_timer=0) so the software hrtimer path is used.
References
Related entries
- Linux kernel (arch/x86/kvm): Guest-supplied array indices in the host's local-APIC emulation (an IPI destination id andCVE-2025-39823 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): The I/O APIC's delayed EOI work was cancelled only after vCPUs were freed, so the workCVE-2026-74517 · Linux kernel (arch/x86/kvm)Critical
- Linux kernel (arch/x86/kvm): A guest that is in SMM and then triple-faults makes SVM take the SHUTDOWN intercept andCVE-2025-37957 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): An emulated MMIO write that straddles a page boundary onto a second MMIO page is splitCVE-2026-31588 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): When KVM failed to program the interrupt remapping table for irq bypass, it left aCVE-2026-72283 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A nested guest can put an out-of-range virtual-processor ID into an enlightened VMCS andCVE-2026-64247 · Linux kernel (arch/x86/kvm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.