Database/Kernel, userspace & hypervisor

Linux KVM/SVM - AVIC IPI virtualization on Hygon Family 18h: AVIC inter-processor-interrupt virtualization is unsafe on
Impact
AVIC inter-processor-interrupt virtualization is unsafe on Hygon Family 18h parts, which are derived from AMD Family 17h. With AVIC active, a guest's IPIs can be delivered incorrectly - interrupt delivery reaching the wrong target is a cross-VM correctness failure on the interrupt path, which is the same seam the Heckler-class attacks exploit.
Who can reach it
From inside a guest VM on affected Hygon silicon with AVIC enabled.
What to do
Fixed in the Linux kernel by disabling AVIC IPI virtualization on affected parts. Distro kernel update plus host reboot. Interim mitigation: disable AVIC in the kvm_amd module parameters (avic=0), which costs some interrupt-heavy performance but needs only a module reload with guests drained. Relevant only if you have Hygon parts in the fleet - worth checking, since they show up in some regional supply chains.
References
Related entries
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2026-68258 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel mlx5_core port / transceiver module EEPROM (MCIA register): The MCIA register can return 32 dwordsCVE-2026-68293 · Linux kernel mlx5_core port / transceiver module EEPROM (MCIA register)High
- Linux kernel (net/xfrm): Outbound policies rejected optional tunnel and BEET templates but never got the same check forCVE-2026-68420 · Linux kernel (net/xfrm)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A memory or reference-count leak in the amdkfd (KFDCVE-2026-68447 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel (arch/x86/kvm): A guest that disables paravirtual EOI while KVM still has a pending PV-EOI request, andCVE-2026-72284 · Linux kernel (arch/x86/kvm)High
- Linux kernel keyrings: out-of-bounds read in keyring_get_key_chunk() from unprivileged add_key(2)CVE-2026-74567 · Linux kernel keyrings (keyring_get_key_chunk description-level chunk)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.