CVE-2026-63806
Description
A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) component. A malicious guest operating system can trigger a host kernel crash, leading to a Denial of Service (DoS). This occurs when the guest performs a specific memory write operation that causes an unaligned memory access during an ioeventfd datamatch check, which then triggers a critical error in the host kernel.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Crash, Exit, or Restart
An attacker that can trigger an assert statement can still lead to a denial of service if the relevant code can be triggered by an attacker, and if the scope of the assert() extends beyond the attacker's own session.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.