CVE-2026-72289
CVE CVE-2026-72289EUVD EUVD-2026-59188Published 2026-08-15T05:55:10.000ZLast changed 2026-08-17T05:42:24.000ZCVSS 9.3
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Check the interrupt is still ours before migrating it vgic_prune_ap_list() drops both ap_list_lock and irq_lock while migrating an interrupt to another vCPU. After reacquiring the locks it only checks that the affinity is unchanged (target_vcpu == vgic_target_oracle(irq)) before moving the interrupt, which assumes that an interrupt whose affinity is preserved is still queued on this vCPU's ap_list. That assumption no longer holds if the interrupt is taken off the ap_list while the locks are dropped. vgic_flush_pending_lpis() removes the interrupt from the list and sets irq->vcpu to NULL, but leaves enabled/pending/target_vcpu untouched. As the interrupt is still enabled and pending, vgic_target_oracle() returns the same target_vcpu, so the affinity check passes and list_del() is run a second time on an entry that has already been removed. Also check that the interrupt is still assigned to this vCPU (irq->vcpu == vcpu) before moving it.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.6.145; patch: 6.12.97; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <0658b09cba7fe866c6cd70cd2dcdfdcabe80328f; patch: 5.10.261; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <654be81c4c637af12709d47c7efc3302cd336513; 4.7; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <0074b82cdfcb5fd13710a0ac308ade68ac6f6fbe; patch: 7.1.5; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <cb3efe1a354f1638726725c3ecee1ce8d1a7e2dc; patch: 5.15.212; patch: 6.1.178; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <79fdd2aa774e44847cd9bb7edc811e73e3dc7bfe; patch: 6.18.40; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <da2d249a39a1881681c303ceea33f38ba1c5bbeb; patch: 7.2; patch: 0; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <3893e1fcf6f306b327a8358dcd1cbd077989a240; 0919e84c0fc1fc73525fdcedefab89ea8460f697 <e363c0bc0226dc5ea5046a88e9a6864b82c45399
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.