Use-after-free in Linux kernel - CVE-2026-80726
Published: September 4, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to a use-after-free in the KVM x86 MMU when creating a child shadow page from an invalid parent shadow page. A local user can trigger KVM to create such a child shadow page to cause memory corruption.
The condition involves an invalid shadow page being present on the list of active MMU pages.
Affected software
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
How to mitigate CVE-2026-80726
bpftool - update to 5.10.0-334.0.0.235
bpftool-debuginfo - update to 5.10.0-334.0.0.235
kernel-debuginfo - update to 5.10.0-334.0.0.235
kernel-debugsource - update to 5.10.0-334.0.0.235
kernel-devel - update to 5.10.0-334.0.0.235
kernel-headers - update to 5.10.0-334.0.0.235
kernel-source - update to 5.10.0-334.0.0.235
kernel-tools - update to 5.10.0-334.0.0.235
kernel-tools-debuginfo - update to 5.10.0-334.0.0.235
kernel-tools-devel - update to 5.10.0-334.0.0.235
perf - update to 5.10.0-334.0.0.235
perf-debuginfo - update to 5.10.0-334.0.0.235
python3-perf - update to 5.10.0-334.0.0.235
python3-perf-debuginfo - update to 5.10.0-334.0.0.235
External References
- https://git.kernel.org/stable/c/0af4711862c5b818204d40b21f0859ad51c230e9
- https://git.kernel.org/stable/c/5ec42d57655c690234c14aece6dd3f209778c1d8
- https://git.kernel.org/stable/c/66bc868a33cf1de43f22a94acd8857e0fe33393f
- https://git.kernel.org/stable/c/9b7984692c18b22d6d61af3f53887fca7fddb0f1
- https://git.kernel.org/stable/c/9f7760a2e962cbda0d096a27d394d14ad4d22928
- https://git.kernel.org/stable/c/f33ecb89d352348ed5e625f6747ac51ede254e1b