Fedora Account System
Red Hat Associate
Red Hat Customer
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O When completing emulation of instruction that generated a userspace exit for I/O, don't recheck L1 intercepts as KVM has already finished that phase of instruction execution, i.e. has already committed to allowing L2 to perform I/O. If L1 (or host userspace) modifies the I/O permission bitmaps during the exit to userspace, KVM will treat the access as being intercepted despite already having emulated the I/O access. Pivot on EMULTYPE_NO_DECODE to detect that KVM is completing emulation. Of the three users of EMULTYPE_NO_DECODE, only complete_emulated_io() (the intended "recipient") can reach the code in question. gp_interception()'s use is mutually exclusive with is_guest_mode(), and complete_emulated_insn_gp() unconditionally pairs EMULTYPE_NO_DECODE with EMULTYPE_SKIP. The bad behavior was detected by a syzkaller program that toggles port I/O interception during the userspace I/O exit, ultimately resulting in a WARN on vcpu->arch.pio.count being non-zero due to KVM no completing emulation of the I/O instruction. WARNING: CPU: 23 PID: 1083 at arch/x86/kvm/x86.c:8039 emulator_pio_in_out+0x154/0x170 [kvm] Modules linked in: kvm_intel kvm irqbypass CPU: 23 UID: 1000 PID: 1083 Comm: repro Not tainted 6.16.0-rc5-c1610d2d66b1-next-vm #74 NONE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 RIP: 0010:emulator_pio_in_out+0x154/0x170 [kvm] PKRU: 55555554 Call Trace: <TASK> kvm_fast_pio+0xd6/0x1d0 [kvm] vmx_handle_exit+0x149/0x610 [kvm_intel] kvm_arch_vcpu_ioctl_run+0xda8/0x1ac0 [kvm] kvm_vcpu_ioctl+0x244/0x8c0 [kvm] __x64_sys_ioctl+0x8a/0xd0 do_syscall_64+0x5d/0xc60 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK>
This comment was flagged as spam, view the edit history to see the original text if required.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:45115 https://access.redhat.com/errata/RHSA-2026:45115
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:45116 https://access.redhat.com/errata/RHSA-2026:45116
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:45192 https://access.redhat.com/errata/RHSA-2026:45192
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:47869 https://access.redhat.com/errata/RHSA-2026:47869
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:48386 https://access.redhat.com/errata/RHSA-2026:48386
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:49030 https://access.redhat.com/errata/RHSA-2026:49030
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:49031 https://access.redhat.com/errata/RHSA-2026:49031
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:51604 https://access.redhat.com/errata/RHSA-2026:51604
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:51603 https://access.redhat.com/errata/RHSA-2026:51603
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.21 Via RHSA-2026:54599 https://access.redhat.com/errata/RHSA-2026:54599
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.20 Via RHSA-2026:54581 https://access.redhat.com/errata/RHSA-2026:54581
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.22 Via RHSA-2026:54769 https://access.redhat.com/errata/RHSA-2026:54769
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2026:54544 https://access.redhat.com/errata/RHSA-2026:54544
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:54553 https://access.redhat.com/errata/RHSA-2026:54553
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2026:54187 https://access.redhat.com/errata/RHSA-2026:54187
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:59091 https://access.redhat.com/errata/RHSA-2026:59091
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2026:56911 https://access.redhat.com/errata/RHSA-2026:56911
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2026:56786 https://access.redhat.com/errata/RHSA-2026:56786
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2026:56853 https://access.redhat.com/errata/RHSA-2026:56853
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2026:60019 https://access.redhat.com/errata/RHSA-2026:60019