CVE-2026-72285
In the Linux kernel, the following vulnerability has been resolved:
KVM: TDX: Reject concurrent change to CPUID entry count
Reject KVM_TDX_INIT_VM if userspace changes cpuid.nent between the initial read and the subsequent copy of the initialization data.
tdx_td_init() first reads user_data->cpuid.nent to size the flexible kvm_tdx_init_vm copy. The copied structure also contains cpuid.nent, and that field can differ from the value used to size the allocation if userspace modifies the input concurrently. setup_tdparams_cpuids() later passes init_vm->cpuid.nent to kvm_find_cpuid_entry2(), which uses it as the array bound for the copied entries.
Leer descripción completaMostrar menos
Require the copied count to match the value used to size the allocation so that CPUID parsing cannot access beyond the entries actually copied.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1005Data from Local Systemcollection75 % - Impacto secundario
T1499.004Application or System Exploitationimpact70 %
Vulnerabilidad local en el kernel de Linux (AV:L, PR:L) que permite a un atacante con privilegios locales leer memoria fuera de límites (información sensible) o causar denegación de servicio mediante una condición de carrera (TOCTOU) en la copia de datos de CPUID en KVM/TDX.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72285",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "0bd0a4a1428baaf4447e95f0832492d9e3d64961",
"lessThan": "d6b5aba65e99531c97b146622a406c75653819d5",
"versionType": "git"
},
{
"status": "affected",
"version": "0bd0a4a1428baaf4447e95f0832492d9e3d64961",
"lessThan": "cfbebb55e5127dc162e73fa8956000055a78606c",
"versionType": "git"
}
],
"programFiles": [
"arch/x86/kvm/vmx/tdx.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/x86/kvm/vmx/tdx.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:21:59.700",
"references": [
{
"url": "https://git.kernel.org/stable/c/cfbebb55e5127dc162e73fa8956000055a78606c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d6b5aba65e99531c97b146622a406c75653819d5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: TDX: Reject concurrent change to CPUID entry count\n\nReject KVM_TDX_INIT_VM if userspace changes cpuid.nent between the\ninitial read and the subsequent copy of the initialization data.\n\ntdx_td_init() first reads user_data->cpuid.nent to size the flexible\nkvm_tdx_init_vm copy. The copied structure also contains cpuid.nent,\nand that field can differ from the value used to size the allocation if\nuserspace modifies the input concurrently. setup_tdparams_cpuids() later\npasses init_vm->cpuid.nent to kvm_find_cpuid_entry2(), which uses it as\nthe array bound for the copied entries.\n\nRequire the copied count to match the value used to size the allocation\nso that CPUID parsing cannot access beyond the entries actually copied."
}
],
"lastModified": "2026-08-17T06:18:31.197",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}