๐Ÿ” CVE Alert

CVE-2026-72283

UNKNOWN 0.0

KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails Nullify irqfd->producer if updating the IRTE for bypass fails, as leaving a dangling pointer will result in a use-after-free if the irqfd is reachable through KVM's routing, but the producer is freed separately. E.g. for VFIO PCI, the producer is embedded in struct "vfio_pci_irq_ctx" and freed when the vector is disabled, which can happen independent of routing updates. [sean: drop PPC change, massage changelog]

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
77e1b8332d1d7aa786f7515e9bd4055def6a1e06 < d1379888cc4230bac647ec24ab83306afbd03e88 77e1b8332d1d7aa786f7515e9bd4055def6a1e06 < d5560b6569cd05ba72c6b33427fbabc6ec46b8cf 77e1b8332d1d7aa786f7515e9bd4055def6a1e06 < ed446e8aa894883c08892cfee69782fdf8f6c3ca
Linux / Linux
6.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d1379888cc4230bac647ec24ab83306afbd03e88 git.kernel.org: https://git.kernel.org/stable/c/d5560b6569cd05ba72c6b33427fbabc6ec46b8cf git.kernel.org: https://git.kernel.org/stable/c/ed446e8aa894883c08892cfee69782fdf8f6c3ca