SB20260816205 - Improper access control in Linux kernel kvm svm
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-74516)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access control in x2APIC MSR interception handling in KVM SVM/AVIC when AVIC is inhibited while an L2 guest is active. A local user can run a nested guest that triggers this state to cause a denial of service.
The issue can allow an L1 guest to read much of the host APIC state, send arbitrary interrupts, and change task priority before host disruption occurs.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/6664a5aea45318f4ec156a729949b474dd6e3159
- https://git.kernel.org/stable/c/7668c58dcf465559dc7a0d2e95e9cb79cf47454b
- https://git.kernel.org/stable/c/7d3aae206663c4e006b25a1c7a20a4029e67da76
- https://git.kernel.org/stable/c/89f9e8398e79c49886766fc24a84c37726231104
- https://git.kernel.org/stable/c/f12373625b4dc9bcc89c41872648878c73bb9272