Database/Kernel, userspace & hypervisor

Linux kernel KVM x86 MMU: use-after-free when a vendor module is reloaded after a failed init
Impact
mmu_destroy_caches() destroys pte_list_desc_cache and mmu_page_header_cache but leaves the pointers dangling in kvm.ko, which stays resident when kvm-intel or kvm-amd is unloaded. If a later vendor module load fails partway through, the error path hands a stale pointer to kmem_cache_destroy() and the slab allocator operates on freed memory. On a virtualized GPU host that runs tenant VMs under KVM this is host-side slab corruption in the hypervisor's page-table machinery. The trigger is narrow: it needs a KVM vendor module unload followed by a reload that fails, which is an administrative sequence, not something a guest can drive.
Who can reach it
Local root on the hypervisor host - whoever can rmmod and modprobe kvm-intel or kvm-amd. Guests cannot reach it; no unauthenticated or tenant-facing path.
What to do
Pick up the stable fix from the linked git.kernel.org commits or your distribution's backport, which requires a host kernel update and a reboot of each hypervisor node - drain VMs first. Until then, avoid unload/reload cycles of the KVM vendor module on live hosts; a clean reboot instead of a module reload sidesteps the bug. The record names no fixed release version.
References
Related entries
- Linux perf/x86/amd/brs - kernel address leakage through Branch Sampling: A user-only branch stack collected via AMDCVE-2026-72237 · Linux perf/x86/amd/brs - kernel address leakage through Branch SamplingUnscored
- Linux BPF verifier: kernel pointers leak through verifier logs for three pseudo ldimm64 sourcesCVE-2026-72402 · Linux kernel BPF verifier (ldimm64 pseudo-pointer masking in verifier logs)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2026-74353 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Memory is handed to a consumer without beingCVE-2026-74448 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel vhost: stale vring metadata cache lets a reconfigured vring access memory outside its IOTLB mappingCVE-2026-74580 · Linux kernel vhost (vring metadata IOTLB cache)Unscored
- Linux kernel BPF sockmap: use-after-free on the cached redirect socket in the send verdict pathCVE-2026-74589 · Linux kernel BPF sockmap (tcp_bpf_send_verdict sk_redir refcount)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.