Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm): The I/O APIC's delayed EOI work was cancelled only after vCPUs were freed, so the work
Impact
The I/O APIC's delayed EOI work was cancelled only after vCPUs were freed, so the work item can fire against destroyed vCPUs and deliver an interrupt through freed memory. KASAN shows a slab use-after-free read in the APIC fast-delivery path - a host kernel UAF that a local process can schedule at will, which is a privilege-escalation primitive on a shared node.
Who can reach it
Any process that can open /dev/kvm: create a VM with an in-kernel I/O APIC, assert a line so the delayed EOI work is queued, then destroy the VM and let the worker run against the freed vCPUs. No guest cooperation needed beyond running the VM. In a cluster this matters wherever tenants get /dev/kvm directly or via nested virtualization.
What to do
Update to a kernel with the fix (the record lists 6.13 as a fixed release; verify against the referenced commits for your stable branch). Interim: keep /dev/kvm out of tenant containers and disable nested virt for tenant VMs.
References
Related entries
- Linux kernel (arch/x86/kvm): A guest that is in SMM and then triple-faults makes SVM take the SHUTDOWN intercept andCVE-2025-37957 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): An emulated MMIO write that straddles a page boundary onto a second MMIO page is splitCVE-2026-31588 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): When KVM failed to program the interrupt remapping table for irq bypass, it left aCVE-2026-72283 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A nested guest can put an out-of-range virtual-processor ID into an enlightened VMCS andCVE-2026-64247 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A guest that is not advertised long mode makes the host's SMM emulator walk 16CVE-2022-49883 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A guest that disables paravirtual EOI while KVM still has a pending PV-EOI request, andCVE-2026-72284 · Linux kernel (arch/x86/kvm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.