Data Handling Vulnerability in KVM for Linux Kernel by QEMU
CVE-2026-63806

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63806?

A vulnerability in the KVM component of the Linux kernel allowed for the potential triggering of a BUG_ON() condition due to improper data alignment during memory access operations. This issue, which had been present since 2009, affected how KVM processed stores that split across multiple pages, particularly in cases with emulated MMIO. A dedicated fix replaced the problematic checks with more reliable alignment handling, ensuring safer data processing within the virtualization environment.

Affected Version(s)

Linux d34e6b175e61821026893ec5298cc8e7558df43a

Linux d34e6b175e61821026893ec5298cc8e7558df43a < 5da9b1a87ec7cc3489c27016313524769f12d9e0

Linux d34e6b175e61821026893ec5298cc8e7558df43a < 5c87b47374682f69686068ad0a7779365a527b1c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.