CVE-2026-80726
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
Explicitly clear role.invalid when deriving a child shadow page's role from
its parent to harden against bugs elsewhere in KVM, as violating KVM's
invariant that invalid pages are NOT on the list of active MMU pages leads
to use-after-free due to _kvmmmupreparezappage() using listadd()
instead of list_move() when processing an invalid shadow page, i.e. makes a
bad situation far worse.
Yell loudly if the parent is invalid, as it means KVM has missed a validity
check, i.e. KVM is attempting to map memory using an invalid/obsolete root,
but continue on as the child is otherwise still a valid shadow page.
==================================================================
BUG: KASAN: slab-use-after-free in _kvmmmugetshadow_page+0x1817/0x1860 [kvm]
Write of size 8 at addr ff11000153dd1368 by task repro/853
CPU: 1 UID: 1000 PID: 853 Comm: repro Not tainted 7.2.0-rc2-3aec122bdcaf-next-vm #5 PREEMPT
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
Call Trace:
<TASK>
dumpstacklvl+0x4b/0x70
print_report+0x153/0x49c
kasan_report+0xbc/0xf0
_kvmmmugetshadow_page+0x1817/0x1860 [kvm]
mmuallocroot+0x141/0x320 [kvm]
kvmmmuload+0x612/0x20f0 [kvm]
kvmarchvcpuioctlrun+0x3dd5/0x6150 [kvm]
kvmvcpuioctl+0x5e4/0x10d0 [kvm]
_x64sys_ioctl+0x131/0x1b0
dosyscall64+0x67/0x5f0
entrySYSCALL64afterhwframe+0x4b/0x53
</TASK>
Allocated by task 853:
kasansavestack+0x20/0x40
kasansavetrack+0x14/0x30
_kasanslab_alloc+0x5f/0x70
kmemcachealloc_noprof+0xfe/0x2e0
_kvmmmutopupmemory_cache+0x135/0x530 [kvm]
paging64pagefault+0x318/0x1e30 [kvm]
kvmmmudopagefault+0x21d/0x630 [kvm]
kvmmmupage_fault+0x18c/0x17b0 [kvm]
kvmarchvcpuioctlrun+0x1f35/0x6150 [kvm]
kvmvcpuioctl+0x5e4/0x10d0 [kvm]
_x64sys_ioctl+0x131/0x1b0
dosyscall64+0x67/0x5f0
entrySYSCALL64afterhwframe+0x4b/0x53
Freed by task 853:
kasansavestack+0x20/0x40
kasansavetrack+0x14/0x30
kasansavefree_info+0x3b/0x60
_kasanslab_free+0x43/0x70
kmemcachefree+0xe2/0x400
kvmmmucommitzappage.part.0+0x1e2/0x310 [kvm]
kvmmmufree_roots+0x283/0x560 [kvm]
kvmarchvcpuioctlrun+0x33c8/0x6150 [kvm]
kvmvcpuioctl+0x5e4/0x10d0 [kvm]
_x64sys_ioctl+0x131/0x1b0
dosyscall64+0x67/0x5f0
entrySYSCALL64afterhwframe+0x4b/0x53
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/0af4711862c5b818204d40b21f0859ad51c230e9, https://git.kernel.org/stable/c/5ec42d57655c690234c14aece6dd3f209778c1d8, https://git.kernel.org/stable/c/66bc868a33cf1de43f22a94acd8857e0fe33393f, https://git.kernel.org/stable/c/9b7984692c18b22d6d61af3f53887fca7fddb0f1, https://git.kernel.org/stable/c/9f7760a2e962cbda0d096a27d394d14ad4d22928, https://git.kernel.org/stable/c/ec4eb5c2ef964bf398f07889265121c316561911, https://git.kernel.org/stable/c/f33ecb89d352348ed5e625f6747ac51ede254e1b, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80726.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80726, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git