SB20260816205 - Improper access control in Linux kernel kvm svm



SB20260816205 - Improper access control in Linux kernel kvm svm

Published: August 16, 2026

Security Bulletin ID SB20260816205
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-74516)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper access control in x2APIC MSR interception handling in KVM SVM/AVIC when AVIC is inhibited while an L2 guest is active. A local user can run a nested guest that triggers this state to cause a denial of service.

The issue can allow an L1 guest to read much of the host APIC state, send arbitrary interrupts, and change task priority before host disruption occurs.


Remediation

Install update from vendor's website.