Bug 2521356 (CVE-2026-74607)
| Summary: | CVE-2026-74607 kernel: KVM: SVM: Serialize accesses to the owner and mirror list with separate lock | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Kernel-based Virtual Machine (KVM) Secure Virtual Machine (SVM) module within the Linux kernel. This vulnerability involves a race condition during the management of encrypted virtual machine contexts, specifically when handling owner and mirror lists. A privileged user or malicious guest virtual machine could exploit this timing issue during concurrent operations, such as virtual machine migration or destruction. This could lead to corruption of internal data structures or incorrect handling of virtual machine resources, potentially resulting in system instability or a denial of service.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-22 15:41:30 UTC
|