{"apiVersion":"1.0","identifier":"CVE-2026-72284","description":"In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs Ignore KVM-s internal -service pending PV EOI- request if the vCPU has disabled PV EOIs since the request was made. Asserting that PV EOIs are enabled can fail if reading guest memory in pv_eoi_get_user() fails, i.e. if pv_eoi_test_and_clr_pending() bails early, *and* the vCPU also disables PV EOIs. kernel BUG at arch/x86/kvm/lapic.c:3338! Oops: invalid opcode: 0000 [#1] SMP CPU: 4 UID: 1000 PID: 890 Comm: pv_eoi_test Not tainted 7.0.0-d585aa5894d8-vm #337 PREEMPT Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 RIP: 0010:kvm_lapic_sync_from_vapic+0x12b/0x140 [kvm] Call Trace: <TASK> kvm_arch_vcpu_ioctl_run+0x1075/0x1c30 [kvm] kvm_vcpu_ioctl+0x2d5/0x980 [kvm] __x64_sys_ioctl+0x8a/0xd0 do_syscall_64+0xb5/0xb40 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK> Modules linked in: kvm_intel kvm irqbypass ---[ end trace 0000000000000000 ]---","publishedAt":"2026-08-15T06:21:59","lastModifiedAt":"2026-08-17T06:18:31","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72284","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","epssProbability":0.00187,"riskScore":0.72,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72284","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72284","en":"https://www.redsauce.net/en/cves/CVE-2026-72284","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72284","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72284","de":"https://www.redsauce.net/de/cves/CVE-2026-72284","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72284","el":"https://www.redsauce.net/el/cves/CVE-2026-72284"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72284"}}