KVM Vulnerability in Linux Kernel Affecting Shadow Page Roles
CVE-2026-80726

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-80726?

A vulnerability exists in the KVM component of the Linux kernel that specifies a failure in handling shadow page roles. This issue arises when creating a child shadow page, where the invalid role of the parent is not checked thoroughly. As a result, it can lead to a use-after-free scenario within the kernel's memory management functions, exposing systems to potential memory corruption and stability issues. The vulnerability emphasizes the importance of validating memory roles to ensure system integrity during virtualization processes.

Affected Version(s)

Linux a770f6f28b1a9287189f3dc8333eb694d9a2f0ab < 9b7984692c18b22d6d61af3f53887fca7fddb0f1

Linux a770f6f28b1a9287189f3dc8333eb694d9a2f0ab

Linux a770f6f28b1a9287189f3dc8333eb694d9a2f0ab < 0af4711862c5b818204d40b21f0859ad51c230e9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.