Junglewise Threat Intelligence

CVE-2026-46295: Linux Kernel KVM race condition in x86 APIC IRR update

CVE-2026-46295 · Severity: info · CVSS 2.1 · Published 2026-06-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition was identified in the Linux kernel's virtualization component (KVM) for x86 processors. This issue occurs when the system handles virtual interrupts between different virtual CPUs. While it does not result in data loss, it can cause the system to trigger internal warnings and perform unnecessary processing cycles, slightly impacting the performance and stability of virtual machine environments.

Technical details

A race condition exists between vmx_sync_pir_to_irr() on a target vCPU and __vmx_deliver_posted_interrupt() on a sender vCPU. The root cause is that the sender performs two individually atomic operations (setting the PIR bit and setting PID.ON) that are not part of a single transaction. This allows an interleaving where the target vCPU clears PID.ON but finds an empty PIR, leading to an early return that fails to scan the Interrupt Request Register (IRR). While interrupts are eventually recovered in subsequent iterations, the immediate failure to report the highest pending vector causes a WARNING in vmx_check_nested_events(). The fix ensures the IRR is scanned even if the PIR is empty when PID.ON was set.

Affected products

  • Linux Linux Kernel x86 KVM component

Timeline

  • 2026-05-03: patched: Initial fix committed to mainline kernel
  • 2026-06-08: disclosed: CVE published

References

Related threats