Database/Kernel, userspace & hypervisor

Linux kernel (virt/kvm): A guest store that splits a page and lands on a datamatch-enabled ioeventfd reaches a BUG_ON
Impact
A guest store that splits a page and lands on a datamatch-enabled ioeventfd reaches a BUG_ON in KVM's ioeventfd handling because of an alignment assumption that does not hold. Impact is denial of service, not escape - but it is a guest hitting a kernel BUG on the host, so on a node with panic_on_oops set it is a whole-node outage for every co-resident tenant.
Who can reach it
Pure guest-side: emit an unaligned store (e.g. a 16-byte store at page offset 0xffc) where the second page carries a datamatch ioeventfd at offset 0 - a virtio doorbell is exactly such an ioeventfd, so every VM with virtio devices has the target. No host privilege needed.
What to do
Update to a kernel with the referenced stable commits. No meaningful interim control - ioeventfds are how virtio doorbells work. Set panic_on_oops deliberately: leaving it off keeps the blast radius to the one VM rather than the node.
References
Related entries
- Linux kernel (virt/kvm): The dirty-ring reset path bounds-checks an offset with unchecked 64-bit arithmetic, so aCVE-2026-52969 · Linux kernel (virt/kvm)High
- Linux kernel (virt/kvm): Unbinding a memslot from a guest_memfd was skipped once the file was already dying, so if theCVE-2025-40274 · Linux kernel (virt/kvm)High
- Linux kernel (virt/kvm): KVM blocked turning KVM_MEM_GUEST_MEMFD on for an existing memslot but not turning it off, andCVE-2025-68810 · Linux kernel (virt/kvm)High
- Linux KVM/SVM - AVIC IPI virtualization on Hygon Family 18h: AVIC inter-processor-interrupt virtualization is unsafe onCVE-2026-64172 · Linux KVM/SVM - AVIC IPI virtualization on Hygon Family 18hHigh
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2026-68258 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel mlx5_core port / transceiver module EEPROM (MCIA register): The MCIA register can return 32 dwordsCVE-2026-68293 · Linux kernel mlx5_core port / transceiver module EEPROM (MCIA register)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.