Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm): When KVM failed to program the interrupt remapping table for irq bypass, it left a
Impact
When KVM failed to program the interrupt remapping table for irq bypass, it left a dangling pointer to the interrupt producer. For VFIO PCI the producer lives inside the per-vector context and is freed when the vector is disabled, so KVM later dereferences freed memory - a host kernel use-after-free in the interrupt path of a passthrough device.
Who can reach it
Requires device passthrough with interrupt bypass - exactly the configuration used for GPU and NIC passthrough in a GPU cloud. A tenant (or the VMM acting on tenant-controlled MSI-X configuration) disables an MSI-X vector on the assigned device while KVM's routing still references the producer; an IRTE update failure leaves the stale pointer behind. Needs /dev/vfio access plus an assigned device, i.e. any tenant VM with a passed-through GPU or NIC.
What to do
Update to a kernel with the referenced stable commits. Interim: there is no clean workaround short of dropping IRQ bypass (disable posted interrupts / kvm halt_poll and IRQ bypass on the node) or not passing devices through, both of which cost GPU-VM performance - patch and reboot is the real fix.
References
Related entries
- Linux kernel (arch/x86/kvm): A nested guest can put an out-of-range virtual-processor ID into an enlightened VMCS andCVE-2026-64247 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A guest that is not advertised long mode makes the host's SMM emulator walk 16CVE-2022-49883 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A guest that disables paravirtual EOI while KVM still has a pending PV-EOI request, andCVE-2026-72284 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A failed RSM leaves the vCPU's SMM flag and the MMU role out of sync, so KVM resolves aCVE-2021-47230 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): The guard against accessing bytes 4-15 of an emulated APIC register was dropped, andCVE-2021-47255 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): A guest using its APIC timer in periodic mode can leave KVM programming an already-expiredCVE-2025-71104 · Linux kernel (arch/x86/kvm)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.