CVE-2026-72283

Source
https://cve.org/CVERecord?id=CVE-2026-72283
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72283.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72283
Downstream
Published
2026-08-15T05:55:06.959Z
Modified
2026-08-18T03:56:40.780818175Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails

Nullify irqfd->producer if updating the IRTE for bypass fails, as leaving a dangling pointer will result in a use-after-free if the irqfd is reachable through KVM's routing, but the producer is freed separately. E.g. for VFIO PCI, the producer is embedded in struct "vfiopciirq_ctx" and freed when the vector is disabled, which can happen independent of routing updates.

[sean: drop PPC change, massage changelog]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72283.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
77e1b8332d1d7aa786f7515e9bd4055def6a1e06
Fixed
d1379888cc4230bac647ec24ab83306afbd03e88
Fixed
d5560b6569cd05ba72c6b33427fbabc6ec46b8cf
Fixed
ed446e8aa894883c08892cfee69782fdf8f6c3ca

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72283.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.17.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72283.json"