{"api_version":"1","generated_at":"2026-09-19T23:04:48+00:00","cve":"CVE-2026-89927","urls":{"html":"https://cve.report/CVE-2026-89927","api":"https://cve.report/api/cve/CVE-2026-89927.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89927","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89927"},"summary":{"title":"KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: hyper-v: Clamp stimer deadline to avoid livelock\n\nFix an issue where userspace or the guest can program an Hyper-V\nsynthetic timer to have a deadline in the past via integer overflow,\npreventing the CPU from making progress and triggering an RCU stall.\n\nHyper-V's SynIC exposes 4 per-vCPU synthetic timers to the\nguest, which are emulated by KVM. Each is programmed through the\nHV_X64_MSR_STIMERi_CONFIG and HV_X64_MSR_STIMERi_COUNT MSRs. Depending\non CONFIG, COUNT represents either the absolute expiration time or the\nperiod of a periodic timer, both expressed in 100ns ticks. These timers\nmay be set both by the guest (WRMSR) and the host (KVM_SET_MSRS).\n\nWhen the timer is enabled, stimer_start() translates COUNT to an\nabsolute monotonic deadline and arms an hrtimer. If COUNT is set to a\nvalue close to U64_MAX, the deadline calculation can overflow.\n\n    ktime_add_ns(ktime_now, 100 * (stimer->exp_time - time_now))\n\nThis can result in a CPU livelock. stimer_start() arms the timer\nvia hrtimer_start() with a deadline in the past, which causes it to\nimmediately fire. The stimer callback then raises KVM_RQ_HV_STIMER, with\nthe intention of causing KVM to deliver a synthetic interrupt on the\nnext vCPU guest enter.\n\nThen, once userspace issues KVM_RUN, vcpu_enter_guest() consumes the\nrequest, calling kvm_hv_process_stimers(). This would normally disable\nthe timer via stimer_expiration() once the deadline is in the past.\nHowever, the deadline comparison is done between the KVM reference\ncounter and stime->exp_time, which is a big value close to U64_MAX, so\nthis never happens for a few thousand years.\n\nkvm_hv_process_timers() then re-arms the timer via stimer_start(), since\nit was not disabled, which again fires immediately. Before entering\nthe guest, kvm_vcpu_exit_request() checks kvm_request_pending(),\nwhich returns true due to the newly raised KVM_REQ_HV_STIMER. Then\nvcpu_enter_guest() aborts the guest entry, returning early into\nvcpu_run(), which loops back again into vcpu_enter_guest(), restarting\nthe cycle.\n\nSince there are no manual yields in this loop, a task with SCHED_FIFO\nmay starve RCU grace-period kthreads, which exposes the stalls found\nby syzcaller:\n\n    rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:\n    rcu:    (detected by 1, t=10502 jiffies, g=14269, q=1142 ncpus=2)\n    rcu: All QSes seen, last rcu_preempt kthread activity 10500 (4294965239-4294954739), jiffies_till_next_fqs=1, root ->qsmask 0x0\n    rcu: rcu_preempt kthread starved for 10500 jiffies! g14269 f0x2 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=0\n    rcu:    Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.\n        ( ... )\n    Call Trace:\n     <IRQ>\n     __run_hrtimer kernel/time/hrtimer.c:1773 [inline]\n     __hrtimer_run_queues+0x408/0xc30 kernel/time/hrtimer.c:1841\n     hrtimer_interrupt+0x45b/0xaa0 kernel/time/hrtimer.c:1903\n     local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1045 [inline]\n     __sysvec_apic_timer_interrupt+0x102/0x3e0 arch/x86/kernel/apic/apic.c:1062\n     instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1056 [inline]\n     sysvec_apic_timer_interrupt+0xa1/0xc0 arch/x86/kernel/apic/apic.c:1056\n     </IRQ>\n     <TASK>\n     asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:697\n    RIP: 0010:__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:152 [inline]\n    RIP: 0010:_raw_spin_unlock_irqrestore+0xa8/0x110 kernel/locking/spinlock.c:194\n    Code: 74 05 e8 0b f4 5f f6 48 c7 44 24 20 00 00 00 00 9c 8f 44 24 20 f6 44 24 21 02 75 4f f7 c3 00 02 00 00 74 01 fb bf 01 00 00 00 <e8> 23 6b 27 f6 65 8b 05 7c 60 5a 07 85 c0 74 40 48 c7 04 24 0e 36\n    RSP: 0018:ffffc900040a7320 EFLAGS: 00000206\n    RAX: 5de15cb931505900 RBX: 0000000000000a06 RCX: 5de15cb931505900\n    RDX: 0000000000000007 RSI: ffffffff8daa9dc3 RDI: 0000000000000001\n    RBP: ffffc900040a73b0 R08: ffffffff8fc3d0\n---truncated---","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:17:01","updated_at":"2026-09-16 15:18:18"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","data":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/8e19ded84336891646b31375720717635f0fdd90","name":"https://git.kernel.org/stable/c/8e19ded84336891646b31375720717635f0fdd90","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a4665762388750e08df99baabe5fce2a21d1423e","name":"https://git.kernel.org/stable/c/a4665762388750e08df99baabe5fce2a21d1423e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3097582b73a8ed1cd6f6790fa78706f4a79b5a49","name":"https://git.kernel.org/stable/c/3097582b73a8ed1cd6f6790fa78706f4a79b5a49","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/61954727ee08f026f5e1c9ee69e1b404a68f2f7a","name":"https://git.kernel.org/stable/c/61954727ee08f026f5e1c9ee69e1b404a68f2f7a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8aa467fe757d8cb2278e98d7fbf44fc05eb0dbf8","name":"https://git.kernel.org/stable/c/8aa467fe757d8cb2278e98d7fbf44fc05eb0dbf8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6a8ba9213cce613455b1502ee0fd178656bf617b","name":"https://git.kernel.org/stable/c/6a8ba9213cce613455b1502ee0fd178656bf617b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/bdb732ebee545b7e3bee7060efc754a8d99818b9","name":"https://git.kernel.org/stable/c/bdb732ebee545b7e3bee7060efc754a8d99818b9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0ca49fbd2883cd53d32d85b50feef17fa04d0fbf","name":"https://git.kernel.org/stable/c/0ca49fbd2883cd53d32d85b50feef17fa04d0fbf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89927","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89927","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1f4b34f825e8cef6f493d06b46605384785b3d16 a4665762388750e08df99baabe5fce2a21d1423e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1f4b34f825e8cef6f493d06b46605384785b3d16 61954727ee08f026f5e1c9ee69e1b404a68f2f7a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1f4b34f825e8cef6f493d06b46605384785b3d16 8aa467fe757d8cb2278e98d7fbf44fc05eb0dbf8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1f4b34f825e8cef6f493d06b46605384785b3d16 8e19ded84336891646b31375720717635f0fdd90 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1f4b34f825e8cef6f493d06b46605384785b3d16 6a8ba9213cce613455b1502ee0fd178656bf617b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1f4b34f825e8cef6f493d06b46605384785b3d16 3097582b73a8ed1cd6f6790fa78706f4a79b5a49 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1f4b34f825e8cef6f493d06b46605384785b3d16 bdb732ebee545b7e3bee7060efc754a8d99818b9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1f4b34f825e8cef6f493d06b46605384785b3d16 0ca49fbd2883cd53d32d85b50feef17fa04d0fbf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.5","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.270 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.221 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.188 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.157 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["arch/x86/kvm/hyperv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"a4665762388750e08df99baabe5fce2a21d1423e","status":"affected","version":"1f4b34f825e8cef6f493d06b46605384785b3d16","versionType":"git"},{"lessThan":"61954727ee08f026f5e1c9ee69e1b404a68f2f7a","status":"affected","version":"1f4b34f825e8cef6f493d06b46605384785b3d16","versionType":"git"},{"lessThan":"8aa467fe757d8cb2278e98d7fbf44fc05eb0dbf8","status":"affected","version":"1f4b34f825e8cef6f493d06b46605384785b3d16","versionType":"git"},{"lessThan":"8e19ded84336891646b31375720717635f0fdd90","status":"affected","version":"1f4b34f825e8cef6f493d06b46605384785b3d16","versionType":"git"},{"lessThan":"6a8ba9213cce613455b1502ee0fd178656bf617b","status":"affected","version":"1f4b34f825e8cef6f493d06b46605384785b3d16","versionType":"git"},{"lessThan":"3097582b73a8ed1cd6f6790fa78706f4a79b5a49","status":"affected","version":"1f4b34f825e8cef6f493d06b46605384785b3d16","versionType":"git"},{"lessThan":"bdb732ebee545b7e3bee7060efc754a8d99818b9","status":"affected","version":"1f4b34f825e8cef6f493d06b46605384785b3d16","versionType":"git"},{"lessThan":"0ca49fbd2883cd53d32d85b50feef17fa04d0fbf","status":"affected","version":"1f4b34f825e8cef6f493d06b46605384785b3d16","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["arch/x86/kvm/hyperv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.5"},{"lessThan":"4.5","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.270","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.221","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.188","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.157","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.270","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.221","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.188","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.157","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"4.5","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: hyper-v: Clamp stimer deadline to avoid livelock\n\nFix an issue where userspace or the guest can program an Hyper-V\nsynthetic timer to have a deadline in the past via integer overflow,\npreventing the CPU from making progress and triggering an RCU stall.\n\nHyper-V's SynIC exposes 4 per-vCPU synthetic timers to the\nguest, which are emulated by KVM. Each is programmed through the\nHV_X64_MSR_STIMERi_CONFIG and HV_X64_MSR_STIMERi_COUNT MSRs. Depending\non CONFIG, COUNT represents either the absolute expiration time or the\nperiod of a periodic timer, both expressed in 100ns ticks. These timers\nmay be set both by the guest (WRMSR) and the host (KVM_SET_MSRS).\n\nWhen the timer is enabled, stimer_start() translates COUNT to an\nabsolute monotonic deadline and arms an hrtimer. If COUNT is set to a\nvalue close to U64_MAX, the deadline calculation can overflow.\n\n    ktime_add_ns(ktime_now, 100 * (stimer->exp_time - time_now))\n\nThis can result in a CPU livelock. stimer_start() arms the timer\nvia hrtimer_start() with a deadline in the past, which causes it to\nimmediately fire. The stimer callback then raises KVM_RQ_HV_STIMER, with\nthe intention of causing KVM to deliver a synthetic interrupt on the\nnext vCPU guest enter.\n\nThen, once userspace issues KVM_RUN, vcpu_enter_guest() consumes the\nrequest, calling kvm_hv_process_stimers(). This would normally disable\nthe timer via stimer_expiration() once the deadline is in the past.\nHowever, the deadline comparison is done between the KVM reference\ncounter and stime->exp_time, which is a big value close to U64_MAX, so\nthis never happens for a few thousand years.\n\nkvm_hv_process_timers() then re-arms the timer via stimer_start(), since\nit was not disabled, which again fires immediately. Before entering\nthe guest, kvm_vcpu_exit_request() checks kvm_request_pending(),\nwhich returns true due to the newly raised KVM_REQ_HV_STIMER. Then\nvcpu_enter_guest() aborts the guest entry, returning early into\nvcpu_run(), which loops back again into vcpu_enter_guest(), restarting\nthe cycle.\n\nSince there are no manual yields in this loop, a task with SCHED_FIFO\nmay starve RCU grace-period kthreads, which exposes the stalls found\nby syzcaller:\n\n    rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:\n    rcu:    (detected by 1, t=10502 jiffies, g=14269, q=1142 ncpus=2)\n    rcu: All QSes seen, last rcu_preempt kthread activity 10500 (4294965239-4294954739), jiffies_till_next_fqs=1, root ->qsmask 0x0\n    rcu: rcu_preempt kthread starved for 10500 jiffies! g14269 f0x2 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=0\n    rcu:    Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.\n        ( ... )\n    Call Trace:\n     <IRQ>\n     __run_hrtimer kernel/time/hrtimer.c:1773 [inline]\n     __hrtimer_run_queues+0x408/0xc30 kernel/time/hrtimer.c:1841\n     hrtimer_interrupt+0x45b/0xaa0 kernel/time/hrtimer.c:1903\n     local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1045 [inline]\n     __sysvec_apic_timer_interrupt+0x102/0x3e0 arch/x86/kernel/apic/apic.c:1062\n     instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1056 [inline]\n     sysvec_apic_timer_interrupt+0xa1/0xc0 arch/x86/kernel/apic/apic.c:1056\n     </IRQ>\n     <TASK>\n     asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:697\n    RIP: 0010:__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:152 [inline]\n    RIP: 0010:_raw_spin_unlock_irqrestore+0xa8/0x110 kernel/locking/spinlock.c:194\n    Code: 74 05 e8 0b f4 5f f6 48 c7 44 24 20 00 00 00 00 9c 8f 44 24 20 f6 44 24 21 02 75 4f f7 c3 00 02 00 00 74 01 fb bf 01 00 00 00 <e8> 23 6b 27 f6 65 8b 05 7c 60 5a 07 85 c0 74 40 48 c7 04 24 0e 36\n    RSP: 0018:ffffc900040a7320 EFLAGS: 00000206\n    RAX: 5de15cb931505900 RBX: 0000000000000a06 RCX: 5de15cb931505900\n    RDX: 0000000000000007 RSI: ffffffff8daa9dc3 RDI: 0000000000000001\n    RBP: ffffc900040a73b0 R08: ffffffff8fc3d0\n---truncated---"}],"metrics":[{"cvssV3_1":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - Guest WRMSR to HV_X64_MSR_STIMERi_CONFIG/COUNT is trapped into KVM (kvm_emulate_wrmsr -> kvm_hv_set_msr_common -> stimer_set_config/count); host userspace can also program the same MSRs via KVM_SET_MSRS, then KVM_RUN. Both paths are local KVM VM-exit/ioctl, not network, adjacent-radio, or physical.\nAC:L - The attacker fully controls COUNT/CONFIG. A one-shot COUNT near U64_MAX deterministically overflows 100*(exp_time-time_now), so hrtimer_start() uses a past deadline and kvm_hv_process_stimers() re-arms forever. CONFIG_KVM_HYPERV defaults to Y and hv-synic/hv-stimer are standard on Windows KVM guests; no race or rare config is required.\nPR:N - The highest-impact case is a cloud x86 KVM tenant whose VM already has Hyper-V CPUID and KVM_CAP_HYPERV_SYNIC (normal for Windows/hv-stimer guests). They WRMSR the stimer MSRs from guest CPL0 with no host root, init-namespace capability, or /dev/kvm access.\nUI:N - The guest programs the synthetic timer during ordinary KVM_RUN; the host vCPU thread livelocks on the same vcpu_enter_guest path with no additional victim action such as mounting a filesystem or opening a file.\nS:C - The retry loop runs in the host KVM vCPU thread (vcpu_run/vcpu_enter_guest) and can stall host CPUs, starve RCU, and OOM the machine, taking down the hypervisor and co-resident VMs and crossing the KVM guest-to-host security boundary.\nC:N - This is an integer overflow in the stimer deadline calculation that only mis-arms an hrtimer; there is no out-of-bounds read, use-after-free, or other host memory disclosure primitive.\nI:N - Host kernel memory is not written or corrupted; the overflowed deadline only produces a KVM_REQ_HV_STIMER/hrtimer retry loop with no arbitrary write or control-flow hijack.\nA:H - stimer_start() re-arms an immediately expiring hrtimer, kvm_vcpu_exit_request() aborts VM-entry, and vcpu_run() loops without a dedicated yield, livelocking the host vCPU thread. A SCHED_FIFO VMM can starve RCU (syzkaller RCU stall and expected OOM), denying service to the host and co-located VMs."}]}],"providerMetadata":{"dateUpdated":"2026-09-16T14:40:17.320Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/a4665762388750e08df99baabe5fce2a21d1423e"},{"url":"https://git.kernel.org/stable/c/61954727ee08f026f5e1c9ee69e1b404a68f2f7a"},{"url":"https://git.kernel.org/stable/c/8aa467fe757d8cb2278e98d7fbf44fc05eb0dbf8"},{"url":"https://git.kernel.org/stable/c/8e19ded84336891646b31375720717635f0fdd90"},{"url":"https://git.kernel.org/stable/c/6a8ba9213cce613455b1502ee0fd178656bf617b"},{"url":"https://git.kernel.org/stable/c/3097582b73a8ed1cd6f6790fa78706f4a79b5a49"},{"url":"https://git.kernel.org/stable/c/bdb732ebee545b7e3bee7060efc754a8d99818b9"},{"url":"https://git.kernel.org/stable/c/0ca49fbd2883cd53d32d85b50feef17fa04d0fbf"}],"title":"KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89927","datePublished":"2026-09-16T10:32:19.473Z","dateReserved":"2026-09-11T19:38:34.775Z","dateUpdated":"2026-09-16T14:40:17.320Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:17:01","lastModifiedDate":"2026-09-16 15:18:18","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":4}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89927","Ordinal":"1","Title":"KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock","CVE":"CVE-2026-89927","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89927","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: hyper-v: Clamp stimer deadline to avoid livelock\n\nFix an issue where userspace or the guest can program an Hyper-V\nsynthetic timer to have a deadline in the past via integer overflow,\npreventing the CPU from making progress and triggering an RCU stall.\n\nHyper-V's SynIC exposes 4 per-vCPU synthetic timers to the\nguest, which are emulated by KVM. Each is programmed through the\nHV_X64_MSR_STIMERi_CONFIG and HV_X64_MSR_STIMERi_COUNT MSRs. Depending\non CONFIG, COUNT represents either the absolute expiration time or the\nperiod of a periodic timer, both expressed in 100ns ticks. These timers\nmay be set both by the guest (WRMSR) and the host (KVM_SET_MSRS).\n\nWhen the timer is enabled, stimer_start() translates COUNT to an\nabsolute monotonic deadline and arms an hrtimer. If COUNT is set to a\nvalue close to U64_MAX, the deadline calculation can overflow.\n\n    ktime_add_ns(ktime_now, 100 * (stimer->exp_time - time_now))\n\nThis can result in a CPU livelock. stimer_start() arms the timer\nvia hrtimer_start() with a deadline in the past, which causes it to\nimmediately fire. The stimer callback then raises KVM_RQ_HV_STIMER, with\nthe intention of causing KVM to deliver a synthetic interrupt on the\nnext vCPU guest enter.\n\nThen, once userspace issues KVM_RUN, vcpu_enter_guest() consumes the\nrequest, calling kvm_hv_process_stimers(). This would normally disable\nthe timer via stimer_expiration() once the deadline is in the past.\nHowever, the deadline comparison is done between the KVM reference\ncounter and stime->exp_time, which is a big value close to U64_MAX, so\nthis never happens for a few thousand years.\n\nkvm_hv_process_timers() then re-arms the timer via stimer_start(), since\nit was not disabled, which again fires immediately. Before entering\nthe guest, kvm_vcpu_exit_request() checks kvm_request_pending(),\nwhich returns true due to the newly raised KVM_REQ_HV_STIMER. Then\nvcpu_enter_guest() aborts the guest entry, returning early into\nvcpu_run(), which loops back again into vcpu_enter_guest(), restarting\nthe cycle.\n\nSince there are no manual yields in this loop, a task with SCHED_FIFO\nmay starve RCU grace-period kthreads, which exposes the stalls found\nby syzcaller:\n\n    rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:\n    rcu:    (detected by 1, t=10502 jiffies, g=14269, q=1142 ncpus=2)\n    rcu: All QSes seen, last rcu_preempt kthread activity 10500 (4294965239-4294954739), jiffies_till_next_fqs=1, root ->qsmask 0x0\n    rcu: rcu_preempt kthread starved for 10500 jiffies! g14269 f0x2 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=0\n    rcu:    Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.\n        ( ... )\n    Call Trace:\n     <IRQ>\n     __run_hrtimer kernel/time/hrtimer.c:1773 [inline]\n     __hrtimer_run_queues+0x408/0xc30 kernel/time/hrtimer.c:1841\n     hrtimer_interrupt+0x45b/0xaa0 kernel/time/hrtimer.c:1903\n     local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1045 [inline]\n     __sysvec_apic_timer_interrupt+0x102/0x3e0 arch/x86/kernel/apic/apic.c:1062\n     instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1056 [inline]\n     sysvec_apic_timer_interrupt+0xa1/0xc0 arch/x86/kernel/apic/apic.c:1056\n     </IRQ>\n     <TASK>\n     asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:697\n    RIP: 0010:__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:152 [inline]\n    RIP: 0010:_raw_spin_unlock_irqrestore+0xa8/0x110 kernel/locking/spinlock.c:194\n    Code: 74 05 e8 0b f4 5f f6 48 c7 44 24 20 00 00 00 00 9c 8f 44 24 20 f6 44 24 21 02 75 4f f7 c3 00 02 00 00 74 01 fb bf 01 00 00 00 <e8> 23 6b 27 f6 65 8b 05 7c 60 5a 07 85 c0 74 40 48 c7 04 24 0e 36\n    RSP: 0018:ffffc900040a7320 EFLAGS: 00000206\n    RAX: 5de15cb931505900 RBX: 0000000000000a06 RCX: 5de15cb931505900\n    RDX: 0000000000000007 RSI: ffffffff8daa9dc3 RDI: 0000000000000001\n    RBP: ffffc900040a73b0 R08: ffffffff8fc3d0\n---truncated---","Type":"Description","Title":"KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock"}]}}}