PT-2026-93568 · Linux · Linux Kernel

CVE-2026-89927

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the KVM x86 Hyper-V synthetic timer emulation where userspace or a guest can program a timer with a deadline in the past by causing an integer overflow. This occurs when the COUNT value is set close to U64 MAX during the deadline calculation in the stimer start() function. This can lead to a CPU livelock, where the timer fires immediately and repeatedly, preventing the CPU from making progress and potentially starving RCU grace-period kthreads, which may result in RCU stalls. The vulnerability involves the HV X64 MSR STIMERi CONFIG and HV X64 MSR STIMERi COUNT MSRs, and affects the stimer start(), kvm hv process stimers(), and vcpu enter guest() functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101225
CVE-2026-89927
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel