SB20260625216 - Out-of-bounds write in Linux kernel kvm
Published: June 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-52969)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in kvm_reset_dirty_gfn() and the KVM dirty ring handling logic when processing rewritten dirty ring entries from a vcpu file descriptor. A local user can modify slot and offset fields in crafted dirty ring entries to cause memory corruption.
The issue is reachable from a process holding /dev/kvm and affects the legacy MMU path with shadow paging, allocated shadow roots, or a write-tracked slot.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/01b71b930f15728aa8599478a7ce90c19dcd9fc2
- https://git.kernel.org/stable/c/0d419c23bb11b5c9664de777c47c1f04a235882d
- https://git.kernel.org/stable/c/0eb281eb95b2d4eea4db1da5fe91023aecc97095
- https://git.kernel.org/stable/c/577a8d3bae0531f0e5ccfac919cd8192f920a804
- https://git.kernel.org/stable/c/74f1a22f7a80f03d28ad8551a2d25d563433addf
- https://git.kernel.org/stable/c/b315b033a877b1ee6d827810b5d7bb4392ffcf8d
- https://git.kernel.org/stable/c/ecf9b3ea7847fe14f34b8c41f00de1eb95c747da