PT-2026-45205 · Unknown · Cloud Hypervisor

CVE-2026-45782

·

Published

2026-05-30

·

Updated

2026-06-10

CVSS v4.0

8.9

High

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Cloud Hypervisor versions 21.0 through 51.1
Description A guest can cause a use-after-free in the cloud-hypervisor process by submitting two virtio-block descriptor chains that reuse the same head index while asynchronous block I/O (such as io uring or aio) is enabled. If the kernel completes the duplicate operation before the original, the completion path frees a bounce buffer that the kernel is still actively reading from or writing to, resulting in memory corruption.
Recommendations Update to version 51.2 or 52.0.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45782
GHSA-F47P-P25Q-83RH
OPENSUSE-SU-2026:10907-1

Affected Products

Cloud Hypervisor