SB2026081694 - Improper Initialization in Linux kernel x86 kvm
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Initialization (CVE-ID: CVE-2026-72284)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the KVM x86 LAPIC PV EOI handling logic when processing PV EOI state synchronization for a vCPU after PV EOIs have been disabled. A local user can trigger this condition to cause a denial of service.
The issue results in a kernel BUG and invalid opcode exception in the KVM subsystem.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/038b9ce6fafda1babd1e33d52cbc6039747a6d87
- https://git.kernel.org/stable/c/32bdca80aa81c2cb906f50a88b220ce1ecdc5e6e
- https://git.kernel.org/stable/c/8e9f7a95279bf608cf4c331ed89612e28c04564f
- https://git.kernel.org/stable/c/9285e4070df2c40585c3d7ec9571faa7a2b97e17
- https://git.kernel.org/stable/c/97542f15dc4cf6cd3fdc035e482dca54246ddf48
- https://git.kernel.org/stable/c/ebd7845ca0471d251a1cb48d84eb165aff5b7123