Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72282— KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 4.8版本存在安全漏洞,该漏洞源于kvm_io_bus_get_dev()函数仅通过地址匹配设备且锁定职责处理不当,可能导致设备生命周期问题,进而引发释放后重用。

CVSS 7.8 · High EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 8a39d00670f0792c1186e442e1dd28fe0326f2ee< f398b7d92cd999191249830b9171c9bd787a9a91 affected
8a39d00670f0792c1186e442e1dd28fe0326f2ee< 1b4a3c2f0509e7b0e65667f3c36676a849ee2755 affected
8a39d00670f0792c1186e442e1dd28fe0326f2ee< cfe107b02a3c3f049e0dc15b6a36625f048eda2a affected
8a39d00670f0792c1186e442e1dd28fe0326f2ee< 90d35d2b8e47afd68fe2a4dd0eeb60bc71641775 affected
8a39d00670f0792c1186e442e1dd28fe0326f2ee< e01071ea006c9b952125ed8b0cc90ac7bd356cce affected
8a39d00670f0792c1186e442e1dd28fe0326f2ee< 7099e7148f81c605bbc319b16ce0131540341560 affected
8a39d00670f0792c1186e442e1dd28fe0326f2ee< 0cbae0e296d27ce4c4cce83e34d40c2bfd8133aa affected
8a39d00670f0792c1186e442e1dd28fe0326f2ee< 3a07249981629ace483ebbef81ef6b34c2d2afec affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-72282

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers kvm_io_bus_get_dev() returns a device that is only matched by the address, and nothing else. This can cause a lifetime issue if the matched device is not the expected type, as by the time the caller can introspect the object, it might be gone (the srcu lock having been dropped). Given that there is only a single user of this helper, the simplest option is to move the locking responsibility to the caller, which can keep the srcu lock held for as long as it wants. Note that this aligns with other kvm_io_bus*() helpers, which already require the srcu lock to be held by the callers.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 4.8版本存在安全漏洞,该漏洞源于kvm_io_bus_get_dev()函数仅通过地址匹配设备且锁定职责处理不当,可能导致设备生命周期问题,进而引发释放后重用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 8a39d00670f0792c1186e442e1dd28fe0326f2ee ~ f398b7d92cd999191249830b9171c9bd787a9a91 -
Linux Linux 4.8 -

II. Public POCs for CVE-2026-72282

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72282

登录查看更多情报信息。

Patches & Fixes for CVE-2026-72282 (8)

Same Patch Batch · Linux · 2026-08-15 · 845 CVEs total

CVE-2026-74280 10.0 CRITICAL crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
CVE-2026-74309 10.0 CRITICAL vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-74279 10.0 CRITICAL crypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-74475 10.0 CRITICAL vxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-72407 10.0 CRITICAL geneve: validate inner network offset in geneve_gro_complete()
CVE-2026-72408 10.0 CRITICAL geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-72421 10.0 CRITICAL ipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-72493 9.9 CRITICAL net: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-72472 9.8 CRITICAL nfs: use nfsi->rwsem to protect traversal of the file lock list
CVE-2026-74428 9.8 CRITICAL rxrpc: Fix double unlock in rxrpc_recvmsg()
CVE-2026-72473 9.8 CRITICAL xprtrdma: Decouple req recycling from RPC completion
CVE-2026-72098 9.8 CRITICAL dm-verity: fix buffer overflow in FEC calculation
CVE-2026-74433 9.8 CRITICAL rxrpc: Fix UAF in rxgk_issue_challenge()
CVE-2026-74434 9.8 CRITICAL rxrpc: Don't move a peeked OOB message onto the pending queue
CVE-2026-72299 9.8 CRITICAL tipc: restrict socket queue dumps in enqueue tracepoints
CVE-2026-72477 9.8 CRITICAL fs/ntfs3: call _ntfs_bad_inode() when failing to rename
CVE-2026-72249 9.8 CRITICAL netfilter: flowtable: use dst in this direction when pushing IPIP header
CVE-2026-72251 9.8 CRITICAL netfilter: nf_nat_sip: reload possible stale data pointer
CVE-2026-72130 9.8 CRITICAL nvmet-auth: reject short AUTH_RECEIVE buffers
CVE-2026-72137 9.8 CRITICAL xfrm: nat_keepalive: avoid double free on send error

Showing top 20 of 845 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-72282

No comments yet


Leave a comment