CVE-2026-72289
CVE CVE-2026-72289EUVD EUVD-2026-59188Veröffentlicht 2026-08-15T05:55:10.000ZZuletzt geändert 2026-08-17T05:42:24.000ZCVSS 9.3
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the interrupt is still ours before migrating it vgic_prune_ap_list() drops both ap_list_lock and irq_lock while migrating an interrupt to another vCPU. After reacquiring the locks it only checks that the affinity is unchanged (target_vcpu == vgic_target_oracle(irq)) before moving the interrupt, which assumes that an interrupt whose affinity is preserved is still queued on this vCPU's ap_list. That assumption no longer holds if the interrupt is taken off the ap_list while the locks are dropped. vgic_flush_pending_lpis() removes the interrupt from the list and sets irq->vcpu to NULL, but leaves enabled/pending/target_vcpu untouched. As the interrupt is still enabled and pending, vgic_target_oracle() returns the same target_vcpu, so the affinity check passes and list_del() is run a second time on an entry that has already been removed. Also check that the interrupt is still assigned to this vCPU (irq->vcpu == vcpu) before moving it.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux patch: 6.6.145; patch: 6.12.97; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <0658b09cba7fe866c6cd70cd2dcdfdcabe80328f; patch: 5.10.261; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <654be81c4c637af12709d47c7efc3302cd336513; 4.7; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <0074b82cdfcb5fd13710a0ac308ade68ac6f6fbe; patch: 7.1.5; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <cb3efe1a354f1638726725c3ecee1ce8d1a7e2dc; patch: 5.15.212; patch: 6.1.178; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <79fdd2aa774e44847cd9bb7edc811e73e3dc7bfe; patch: 6.18.40; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <da2d249a39a1881681c303ceea33f38ba1c5bbeb; patch: 7.2; patch: 0; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <3893e1fcf6f306b327a8358dcd1cbd077989a240; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <e363c0bc0226dc5ea5046a88e9a6864b82c45399
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.