CRITICAL Introduced in 4.7
kvm ApList UAF
CVE-2026-72289
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
KernelScan AI7.8HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the interrupt is still ours before migrating it vgic_prune_ap_list() drops both ap_list_lock and irq_lock while migrating an interrupt to another vCPU. After reacquiring the locks it only checks that the affinity is unchanged (target_vcpu == vgic_target_oracle(irq)) before moving the interrupt, which assumes that an interrupt whose affinity is preserved is still queued on this vCPU's ap_list. That assumption no longer holds if the interrupt is taken off the ap_list while the locks are dropped. vgic_flush_pending_lpis() removes the interrupt from the list and sets irq->vcpu to NULL, but leaves enabled/pending/target_vcpu untouched. As the interrupt is still enabled and pending, vgic_target_oracle() returns the same target_vcpu, so the affinity check passes and list_del() is run a second time on an entry that has already been removed. Also check that the interrupt is still assigned to this vCPU (irq->vcpu == vcpu) before moving it.
02KernelScan AI Analysis
Risk summary
A race condition in the KVM ARM64 virtual interrupt controller allows a malicious guest VM to corrupt host kernel memory by triggering a double removal of an interrupt from a pending list. This is a guest-to-host escape primitive: any code running inside a KVM guest on ARM64 can trigger the race, potentially leading to arbitrary kernel memory corruption on the host. Systems running KVM virtual machines with untrusted guests are at risk.
Vulnerability analysis
The KVM ARM64 virtual interrupt controller has a race condition in the path that migrates pending interrupts between virtual CPUs. During migration the code temporarily releases its locks, and if another operation removes the interrupt from the pending list during that window, the migration code will attempt to remove it a second time — corrupting the linked list and surrounding kernel heap. The fix adds a check that the interrupt is still assigned to the current virtual CPU before proceeding with the migration, aborting safely if it has been taken off the list in the meantime. This vulnerability is reachable from inside a running KVM guest on ARM64: any code executing in the guest can generate the interrupt activity needed to race these code paths, making it a guest-to-host escape primitive on any system running KVM virtual machines.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.15 | 4.7 | 5.15.212 | cb3efe1a354f |
| 6.6 | 4.7 | 6.6.145 | 654be81c4c63 |
| 6.18 | 4.7 | 6.18.40 | 79fdd2aa774e |
| 7.1 | 4.7 | 7.1.5 | 0658b09cba7f |
| mainline | 4.7 | 7.2-rc4 | 0074b82cdfcb |
| 5.10 | 4.7 | 5.10.261 | 3893e1fcf6f3 |
| 6.1 | 4.7 | 6.1.178 | da2d249a39a1 |
| 6.12 | 4.7 | 6.12.97 | e363c0bc0226 |