{"api_version":"1","generated_at":"2026-09-17T08:44:15+00:00","cve":"CVE-2026-72288","urls":{"html":"https://cve.report/CVE-2026-72288","api":"https://cve.report/api/cve/CVE-2026-72288.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-72288","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-72288"},"summary":{"title":"KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling\n\nHyunwoo Kim reports some really bad races should the following\nsituation occur:\n\n- LPI-I is pending in vcpu-B's AP list\n- vcpu-A writes to vcpu-B's RD to disable its LPIs\n- vcpu-C moves I from B to C\n\nIf the last two race nicely enough, vgic_prune_ap_list() can drop\nthe irq and AP list locks, reacquire them, and in the interval\nthe irq has been freed. UAF follows.\n\nThe fix is two-fold:\n\n- Before dropping the irq and ap_list locks, take a reference on\n  the irq\n\n- Do not try to handle migration of the pending bit: there is no\n  expectation that this state is retained, as per the architecture\n\nWith that, we're sure that the interrupt is still around, and we\nsafely remove it from the AP list as it has no target at this\nstage (unless another interrupt fires, but that's another story).","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:22:00","updated_at":"2026-08-17 06:18:31"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.3","severity":"CRITICAL","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.3","severity":"CRITICAL","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":9.3,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/7258770e5814f15e8308ebda82ac9acf6964ba8e","name":"https://git.kernel.org/stable/c/7258770e5814f15e8308ebda82ac9acf6964ba8e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b1a89d12d35a8256d2b170ced0b1c86851f3def2","name":"https://git.kernel.org/stable/c/b1a89d12d35a8256d2b170ced0b1c86851f3def2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d19dca8194ebed371e624331c6be2cb73b562caf","name":"https://git.kernel.org/stable/c/d19dca8194ebed371e624331c6be2cb73b562caf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-72288","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72288","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5dd4b924e390af426e424d5e52c1b4d1566af817 d19dca8194ebed371e624331c6be2cb73b562caf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5dd4b924e390af426e424d5e52c1b4d1566af817 b1a89d12d35a8256d2b170ced0b1c86851f3def2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5dd4b924e390af426e424d5e52c1b4d1566af817 7258770e5814f15e8308ebda82ac9acf6964ba8e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.8","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"72288","cve":"CVE-2026-72288","epss":"0.001780000","percentile":"0.076350000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:47"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["arch/arm64/kvm/vgic/vgic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"d19dca8194ebed371e624331c6be2cb73b562caf","status":"affected","version":"5dd4b924e390af426e424d5e52c1b4d1566af817","versionType":"git"},{"lessThan":"b1a89d12d35a8256d2b170ced0b1c86851f3def2","status":"affected","version":"5dd4b924e390af426e424d5e52c1b4d1566af817","versionType":"git"},{"lessThan":"7258770e5814f15e8308ebda82ac9acf6964ba8e","status":"affected","version":"5dd4b924e390af426e424d5e52c1b4d1566af817","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["arch/arm64/kvm/vgic/vgic.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.8"},{"lessThan":"4.8","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"4.8","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling\n\nHyunwoo Kim reports some really bad races should the following\nsituation occur:\n\n- LPI-I is pending in vcpu-B's AP list\n- vcpu-A writes to vcpu-B's RD to disable its LPIs\n- vcpu-C moves I from B to C\n\nIf the last two race nicely enough, vgic_prune_ap_list() can drop\nthe irq and AP list locks, reacquire them, and in the interval\nthe irq has been freed. UAF follows.\n\nThe fix is two-fold:\n\n- Before dropping the irq and ap_list locks, take a reference on\n  the irq\n\n- Do not try to handle migration of the pending bit: there is no\n  expectation that this state is retained, as per the architecture\n\nWith that, we're sure that the interrupt is still around, and we\nsafely remove it from the AP list as it has no target at this\nstage (unless another interrupt fires, but that's another story)."}],"metrics":[{"cvssV3_1":{"baseScore":9.3,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is reached only from KVM guest MMIO traps on GICv3 redistributor GICR_CTLR LPI-disable writes, ITS MOVI affinity changes, and vCPU-exit paths into vgic_prune_ap_list(); no network-facing host protocol is involved.\nAC:L - A guest controls all three racing vCPUs by pinning threads to concurrently issue ITS MOVI, cross-vCPU GICR_CTLR LPI-disable writes, and vCPU exits that invoke vgic_prune_ap_list(); the attacker creates and wins the race rather than depending on uncontrollable host timing.\nPR:N - No host privileges are required beyond running code in an assigned KVM guest (e.g. a cloud VM tenant on arm64); exploitation needs guest-kernel access to GIC/ITS MMIO, not host root or capabilities in the init namespace.\nUI:N - Exploitation is fully attacker-driven from within a multi-vCPU guest VM and does not require any victim user or administrator action on the host.\nS:C - The use-after-free corrupts host-kernel heap memory (struct vgic_irq) from guest-controlled VGIC operations, crossing the guest-to-host virtualization security boundary with VM-escape impact.\nC:H - vgic_flush_pending_lpis() can free the LPI vgic_irq while vgic_prune_ap_list() still dereferences it after reacquiring dropped locks, yielding a kernel heap use-after-free exploitable for arbitrary host memory disclosure via heap grooming.\nI:H - The dangling vgic_irq pointer permits attacker-influenced writes through irq_lock, list_head, vcpu, and target_vcpu fields during ap_list migration, enabling host control-flow or data corruption primitives.\nA:H - The race frees live kernel objects still referenced by the ap_list migration path, causing host kernel oops, panic, or hang during list_del, lock operations, or subsequent LPI delivery on arm64 KVM hosts."}]}],"providerMetadata":{"dateUpdated":"2026-08-17T05:42:23.669Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/d19dca8194ebed371e624331c6be2cb73b562caf"},{"url":"https://git.kernel.org/stable/c/b1a89d12d35a8256d2b170ced0b1c86851f3def2"},{"url":"https://git.kernel.org/stable/c/7258770e5814f15e8308ebda82ac9acf6964ba8e"}],"title":"KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-72288","datePublished":"2026-08-15T05:55:10.256Z","dateReserved":"2026-08-09T03:40:39.917Z","dateUpdated":"2026-08-17T05:42:23.669Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:22:00","lastModifiedDate":"2026-08-17 06:18:31","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"72288","Ordinal":"1","Title":"KVM: arm64: vgic: Handle race between interrupt affinity change ","CVE":"CVE-2026-72288","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"72288","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling\n\nHyunwoo Kim reports some really bad races should the following\nsituation occur:\n\n- LPI-I is pending in vcpu-B's AP list\n- vcpu-A writes to vcpu-B's RD to disable its LPIs\n- vcpu-C moves I from B to C\n\nIf the last two race nicely enough, vgic_prune_ap_list() can drop\nthe irq and AP list locks, reacquire them, and in the interval\nthe irq has been freed. UAF follows.\n\nThe fix is two-fold:\n\n- Before dropping the irq and ap_list locks, take a reference on\n  the irq\n\n- Do not try to handle migration of the pending bit: there is no\n  expectation that this state is retained, as per the architecture\n\nWith that, we're sure that the interrupt is still around, and we\nsafely remove it from the AP list as it has no target at this\nstage (unless another interrupt fires, but that's another story).","Type":"Description","Title":"KVM: arm64: vgic: Handle race between interrupt affinity change "}]}}}