Race condition in Linux kernel - CVE-2026-80895
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause use of partially initialized virtual processor fields.
The vulnerability exists due to improper synchronization in the MSHV pt_vp_array publication path when an irqfd fast-path assertion races concurrent virtual processor creation. A local user can register an irqfd targeting an as-yet-uncreated virtual processor and trigger the fast path concurrently with its creation to cause use of partially initialized virtual processor fields.
The condition can occur on weakly ordered architectures, where a non-NULL array pointer may become visible before virtual processor initialization stores.