PT-2026-72968 · Linux · Linux Kernel
CVE-2026-74516
·
Published
2026-08-15
·
Updated
2026-08-18
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the KVM SVM implementation where x2APIC MSR intercepts for L1 are not updated when AVIC (Advanced Virtual Interrupt Controller) is deactivated while L2 is active. If AVIC is enabled before running L2 and subsequently inhibited during L2 activity, KVM runs L1 with AVIC disabled but keeps x2APIC MSR intercepts disabled. This allows L1 to read most of the host's APIC state, send arbitrary interrupts, and change task priority, which can lead to a Denial of Service (DoS) on the host. The issue can be triggered by abusing the
kvm set posted intr wakeup handler() function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel