SB20260812101 - Use-after-free in Linux kernel kvm mmu
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-68428)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the KVM x86 MMU cache cleanup logic when reloading a vendor module after a prior unload. A local user can trigger a vendor module reload sequence with a failed cache initialization to cause a denial of service.
The issue occurs when kvm.ko remains loaded while a vendor module is unloaded and then reloaded, leaving a stale cache pointer that is later passed to kmem_cache_destroy().
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/32b9f89ed9e6d7a45075d64089c254a7f6e13695
- https://git.kernel.org/stable/c/43cfb20d62ffe49626d62beecfc32eb6f262191c
- https://git.kernel.org/stable/c/52f2f7c30126037975389aa04d24c506a5177c35
- https://git.kernel.org/stable/c/6f4be73880302d5642c83a0813fdfe1f5fd4b6e3
- https://git.kernel.org/stable/c/ec9daa8fd1b6f45545c9839dca55bd867fad9e13