PT-2026-93568 · Linux · Linux Kernel
CVE-2026-89927
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the KVM x86 Hyper-V synthetic timer emulation where userspace or a guest can program a timer with a deadline in the past by causing an integer overflow. This occurs when the
COUNT value is set close to U64 MAX during the deadline calculation in the stimer start() function. This can lead to a CPU livelock, where the timer fires immediately and repeatedly, preventing the CPU from making progress and potentially starving RCU grace-period kthreads, which may result in RCU stalls. The vulnerability involves the HV X64 MSR STIMERi CONFIG and HV X64 MSR STIMERi COUNT MSRs, and affects the stimer start(), kvm hv process stimers(), and vcpu enter guest() functions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel