PT-2026-8206 · Kvm+5 · Kvm+5
Published
2026-01-01
·
Updated
2026-05-22
·
CVE-2026-23198
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.19.0-smp--5dddc257e6b2-irqfd #31
Description
A flaw exists in the Linux kernel's KVM implementation related to handling KVM IRQFD deassignment. Specifically, the code incorrectly clobbers the irqfd's routing type, leading to issues with IRQ bypass functionality on x86 and arm64 architectures. This can result in incorrect IRQ handling, potentially causing NULL pointer dereferences (observed on AMD systems) or list corruption. The issue arises from failing to verify the irqfd's active status before consuming routing information, and can manifest as a kernel NULL pointer dereference or list corruption.
Recommendations
Update to Linux kernel version 6.19.0-smp--5dddc257e6b2-irqfd #31 or a later version that includes the fix.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amd
Kvm
Linux Kernel
Ubuntu
Arm64
X86