CRITICAL Introduced in 4.8
kvm VgicLpi UAF
CVE-2026-72288
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
KernelScan AI7.7HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling Hyunwoo Kim reports some really bad races should the following situation occur: - LPI-I is pending in vcpu-B's AP list - vcpu-A writes to vcpu-B's RD to disable its LPIs - vcpu-C moves I from B to C If the last two race nicely enough, vgic_prune_ap_list() can drop the irq and AP list locks, reacquire them, and in the interval the irq has been freed. UAF follows. The fix is two-fold: - Before dropping the irq and ap_list locks, take a reference on the irq - Do not try to handle migration of the pending bit: there is no expectation that this state is retained, as per the architecture With that, we're sure that the interrupt is still around, and we safely remove it from the AP list as it has no target at this stage (unless another interrupt fires, but that's another story).
02KernelScan AI Analysis
Risk summary
A malicious KVM guest on an arm64 host with GICv3/ITS can exploit a race in the VGIC interrupt migration path to trigger a use-after-free in host kernel memory. This could allow a guest VM to escape its sandbox and gain arbitrary read/write access to the host kernel, compromising the host and all co-located VMs. The bug requires arm64 hardware with GICv3 support and a guest capable of coordinating multi-vCPU timing.
Vulnerability analysis
When one virtual CPU migrates a pending interrupt to another vCPU, the virtualization code temporarily drops its internal locks and reacquires them in a different order. During that unlocked window, a concurrent operation that disables interrupts on the target vCPU can remove and free the interrupt object. When the migration path reacquires the locks, it dereferences the freed object, resulting in a use-after-free in host kernel memory. The fix acquires a reference on the interrupt object before releasing the locks so it cannot be freed during the window, and clears the pending state when flushing interrupts so migration of that state is no longer attempted. A malicious guest VM running on an arm64 KVM host with GICv3/ITS support can reach this by coordinating multiple vCPUs to trigger the race, potentially escaping the VM sandbox to corrupt host kernel memory.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| mainline | 4.8 | 7.2-rc4 | 7258770e5814 |
| 7.1 | 4.8 | 7.1.5 | b1a89d12d35a |
| 6.18 | 4.8 | 6.18.40 | d19dca8194eb |