Bug 2536950 (CVE-2026-81627) - CVE-2026-81627 qemu-kvm: VAPIC writable ROM alias can escape the option-ROM window and expose locked SMRAM
Summary: CVE-2026-81627 qemu-kvm: VAPIC writable ROM alias can escape the option-ROM w...
Keywords:
Status: NEW
Alias: CVE-2026-81627
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2536972 2536973
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-18 09:53 UTC by Mauro Matteo Cascella
Modified: 2026-09-21 10:55 UTC (History)
24 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Mauro Matteo Cascella 2026-09-18 09:53:45 UTC
A flaw was found in QEMU's VAPIC (Virtual Advanced Programmable Interrupt Controller) implementation in hw/i386/vapic.c. The 16-bit VAPIC setup hypercall allows a privileged guest to specify both the base address and size of a high-priority writable RAM alias. QEMU does not validate that this alias remains within the VAPIC option ROM boundaries (0xc0000..0xdffff). A malicious guest administrator can place the alias over 0xa0000..0xbffff, bypassing the Q35 chipset's D_LCK-protected SMRAM and modifying memory that executes in System Management Mode. This could allow a privileged guest user to inject arbitrary code into locked SMRAM.

Upstream fix: https://gitlab.com/qemu-project/qemu/-/commit/d61c8a6fb7388486353aa267ba0d75b098f16662

Reference: https://gitlab.com/qemu-project/qemu/-/work_items/4206


Note You need to log in before you can comment on or make changes to this bug.