Bug 2536973 - CVE-2026-81627 qemu: VAPIC writable ROM alias can escape the option-ROM window and expose locked SMRAM [fedora-all]
Summary: CVE-2026-81627 qemu: VAPIC writable ROM alias can escape the option-ROM windo...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: qemu
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Fedora Virtualization Maintainers
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["ef621f7d-ef08-4087-8b3a-a...
Depends On:
Blocks: CVE-2026-81627
TreeView+ depends on / blocked
 
Reported: 2026-09-18 10:41 UTC by Mauro Matteo Cascella
Modified: 2026-09-18 10:41 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Mauro Matteo Cascella 2026-09-18 10:41:30 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A flaw was found in QEMU's VAPIC (Virtual Advanced Programmable Interrupt Controller) implementation in hw/i386/vapic.c. The 16-bit VAPIC setup hypercall allows a privileged guest to specify both the base address and size of a high-priority writable RAM alias. QEMU does not validate that this alias remains within the VAPIC option ROM boundaries (0xc0000..0xdffff). A malicious guest administrator can place the alias over 0xa0000..0xbffff, bypassing the Q35 chipset's D_LCK-protected SMRAM and modifying memory that executes in System Management Mode. This could allow a privileged guest user to inject arbitrary code into locked SMRAM.

Upstream fix: https://gitlab.com/qemu-project/qemu/-/commit/d61c8a6fb7388486353aa267ba0d75b098f16662

Reference: https://gitlab.com/qemu-project/qemu/-/work_items/4206


Note You need to log in before you can comment on or make changes to this bug.