Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-80726

KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
Back to all
CVE

CVE-2026-80726

KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page

Explicitly clear role.invalid when deriving a child shadow page's role from

its parent to harden against bugs elsewhere in KVM, as violating KVM's

invariant that invalid pages are NOT on the list of active MMU pages leads

to use-after-free due to _kvmmmupreparezappage() using listadd()

instead of list_move() when processing an invalid shadow page, i.e. makes a

bad situation far worse.

Yell loudly if the parent is invalid, as it means KVM has missed a validity

check, i.e. KVM is attempting to map memory using an invalid/obsolete root,

but continue on as the child is otherwise still a valid shadow page.

  ==================================================================

  BUG: KASAN: slab-use-after-free in _kvmmmugetshadow_page+0x1817/0x1860 [kvm]

  Write of size 8 at addr ff11000153dd1368 by task repro/853

  CPU: 1 UID: 1000 PID: 853 Comm: repro Not tainted 7.2.0-rc2-3aec122bdcaf-next-vm #5 PREEMPT

  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015

  Call Trace:

   <TASK>

   dumpstacklvl+0x4b/0x70

   print_report+0x153/0x49c

   kasan_report+0xbc/0xf0

   _kvmmmugetshadow_page+0x1817/0x1860 [kvm]

   mmuallocroot+0x141/0x320 [kvm]

   kvmmmuload+0x612/0x20f0 [kvm]

   kvmarchvcpuioctlrun+0x3dd5/0x6150 [kvm]

   kvmvcpuioctl+0x5e4/0x10d0 [kvm]

   _x64sys_ioctl+0x131/0x1b0

   dosyscall64+0x67/0x5f0

   entrySYSCALL64afterhwframe+0x4b/0x53

   </TASK>

  Allocated by task 853:

   kasansavestack+0x20/0x40

   kasansavetrack+0x14/0x30

   _kasanslab_alloc+0x5f/0x70

   kmemcachealloc_noprof+0xfe/0x2e0

   _kvmmmutopupmemory_cache+0x135/0x530 [kvm]

   paging64pagefault+0x318/0x1e30 [kvm]

   kvmmmudopagefault+0x21d/0x630 [kvm]

   kvmmmupage_fault+0x18c/0x17b0 [kvm]

   kvmarchvcpuioctlrun+0x1f35/0x6150 [kvm]

   kvmvcpuioctl+0x5e4/0x10d0 [kvm]

   _x64sys_ioctl+0x131/0x1b0

   dosyscall64+0x67/0x5f0

   entrySYSCALL64afterhwframe+0x4b/0x53

  Freed by task 853:

   kasansavestack+0x20/0x40

   kasansavetrack+0x14/0x30

   kasansavefree_info+0x3b/0x60

   _kasanslab_free+0x43/0x70

   kmemcachefree+0xe2/0x400

   kvmmmucommitzappage.part.0+0x1e2/0x310 [kvm]

   kvmmmufree_roots+0x283/0x560 [kvm]

   kvmarchvcpuioctlrun+0x33c8/0x6150 [kvm]

   kvmvcpuioctl+0x5e4/0x10d0 [kvm]

   _x64sys_ioctl+0x131/0x1b0

   dosyscall64+0x67/0x5f0

   entrySYSCALL64afterhwframe+0x4b/0x53

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.3
-
3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/0af4711862c5b818204d40b21f0859ad51c230e9, https://git.kernel.org/stable/c/5ec42d57655c690234c14aece6dd3f209778c1d8, https://git.kernel.org/stable/c/66bc868a33cf1de43f22a94acd8857e0fe33393f, https://git.kernel.org/stable/c/9b7984692c18b22d6d61af3f53887fca7fddb0f1, https://git.kernel.org/stable/c/9f7760a2e962cbda0d096a27d394d14ad4d22928, https://git.kernel.org/stable/c/ec4eb5c2ef964bf398f07889265121c316561911, https://git.kernel.org/stable/c/f33ecb89d352348ed5e625f6747ac51ede254e1b, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80726.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80726, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.3

CVSS Score
0
10

Basic Information

Base CVSS
9.3
EPSS Probability
0.0019%
EPSS Percentile
0.07943%
Introduced Version
a770f6f28b1a9287189f3dc8333eb694d9a2f0ab,2.6.30,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
5ec42d57655c690234c14aece6dd3f209778c1d8,5.15.222,6.1.183,6.6.152,6.12.104,6.18.45,7.1.9,6.1.187-1,6.12.107-1~deb12u1,6.12.105-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek,1:6.1.186-228.374.amzn2023,1:1.0-0.amzn2023,1:6.18.48-107.148.amzn2023

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading