Junglewise Threat Intelligence

CVE-2026-72380: Linux kernel Xen pvcalls out-of-bounds write in event handler

CVE-2026-72380 · Severity: high · CVSS 8.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Xen paravirtualized socket (pvcalls) frontend implementation fails to validate a request ID from the backend before using it as an array index, allowing a malicious or buggy backend to write past the bounds of kernel memory. This can lead to kernel memory corruption and system crash or potential code execution in virtualized environments using Xen.

Technical details

The vulnerability is an out-of-bounds write (CWE-787) in the pvcalls_front_event_handler() function in drivers/xen/pvcalls-front.c. The handler reads req_id directly from a backend-supplied ring response and uses it to index the fixed-size bedata->rsp[] array without validation. An attacker controlling the Xen backend can set req_id to any value, including out-of-range values. Additionally, req_id was incorrectly declared as a signed int while the wire protocol field is u32, allowing a value of 0xffffffff to become -1 and pass a bounds check, indexing at negative offsets. The fix bounds-checks req_id as u32, disables the frontend on protocol violation, and prevents further responses from a misbehaving backend. This is most relevant in confidential computing and disaggregated deployment scenarios where backends may be untrusted.

Affected products

  • Linux Linux kernel multiple versions (patched in stable trees from 2.6.11.y through 7.2.y)

Timeline

  • 2026-08-15: disclosed
  • 2026-07-24: patched: Fix merged into stable trees; upstream commit d33846c8dcc06b83b7acdeac1e8bfbb5c0c26cb2

References

Related threats