{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-63806",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-07-19T07:54:57.013Z",
        "datePublished": "2026-07-19T12:02:10.209Z",
        "dateUpdated": "2026-08-17T04:51:12.196Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-17T04:51:12.196Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()\n\nDrop a BUG_ON() that has been reachable since it was first added, way back\nin 2009, and instead use get_unaligned() to perform potentially-unaligned\naccesses.\n\nFor a given store, KVM x86's emulator tracks the entire value in the\ndestination operand, x86_emulate_ctxt.dst.  If the destination is memory,\nand the target splits multiple pages and/or is emulated MMIO, then KVM\nhandles each fragment independently.  E.g. on a page split starting at page\noffset 0xffc, KVM writes 4 bytes to the first page, then the remaining\nbytes to the second page, using ctxt->dst as the source for both (with\nappropriate offsets).\n\nIf the destination splits a page *and* hits emulated MMIO on the second\npage, then KVM will complete the write to the first page, then emulate the\nMMIO access to the second page.  If there is a datamatch-enabled ioeventfd\nat offset 0 of the second page, then KVM will process the remainder of the\nstore as a potential ioeventfd signal.\n\nPutting it all together, if the guest emits a store that splits a page\nstarting at page offset N, and the second page has a datamatch-enabled\nioeventfd at offset 0, then KVM will check for datamatch using\n&dst.valptr[N] as the source.  Due to dst (and thus dst.valptr) being\n32-byte aligned, if N is not aligned to @len, the BUG_ON() fires.\n\nE.g. with a 16-byte store at page offset 0xffc, to an ioeventfd of len 8,\nall initial checks in ioeventfd_in_range() will succeed, and the BUG_ON()\nfires due to @val being 4-byte aligned, but not 8-byte aligned.\n\n  ------------[ cut here ]------------\n  kernel BUG at arch/x86/kvm/../../../virt/kvm/eventfd.c:783!\n  Oops: invalid opcode: 0000 [#1] SMP\n  CPU: 0 UID: 1000 PID: 615 Comm: repro Not tainted 7.1.0-rc2-ff238429d1ea #365 PREEMPT\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n  RIP: 0010:ioeventfd_write+0x6c/0x70 [kvm]\n  Call Trace:\n   <TASK>\n   __kvm_io_bus_write+0x85/0xb0 [kvm]\n   kvm_io_bus_write+0x53/0x80 [kvm]\n   vcpu_mmio_write+0x66/0xf0 [kvm]\n   emulator_read_write_onepage+0x12a/0x540 [kvm]\n   emulator_read_write+0x109/0x2b0 [kvm]\n   x86_emulate_insn+0x4f8/0xfb0 [kvm]\n   x86_emulate_instruction+0x181/0x790 [kvm]\n   kvm_mmu_page_fault+0x313/0x630 [kvm]\n   vmx_handle_exit+0x18a/0x590 [kvm_intel]\n   kvm_arch_vcpu_ioctl_run+0xc81/0x1c90 [kvm]\n   kvm_vcpu_ioctl+0x2d5/0x970 [kvm]\n   __x64_sys_ioctl+0x8a/0xd0\n   do_syscall_64+0xb7/0x890\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n  RIP: 0033:0x7f19c931a9bf\n   </TASK>\n  Modules linked in: kvm_intel kvm irqbypass\n  ---[ end trace 0000000000000000 ]---\n\nIn a perfect world, the fix would be to simply delete the BUG_ON(), as KVM\nx86 doesn't perform alignment checks on \"normal\" memory accesses at CPL0.\nSadly, C99 ruins all the fun; while the x86 architecture plays nice,\ndereferencing an unaligned pointer directly is undefined behavior in C,\ne.g. triggers splats when running with CONFIG_UBSAN_ALIGNMENT=y."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - A malicious KVM guest triggers this via guest-executed MMIO stores handled by the x86 instruction emulator (KVM_RUN → vmx_handle_exit → kvm_mmu_page_fault → x86_emulate_instruction → emulator_read_write → vcpu_mmio_write → ioeventfd_write), not via remote network input to the host.\nAC:L - The guest fully controls the spanning store address, size, and timing; with standard QEMU/virtio datamatch ioeventfd MMIO layouts, a page-boundary write reliably reaches ioeventfd_in_range() with a misaligned val pointer and fires the BUG_ON().\nPR:N - Exploitation requires only unprivileged code execution inside an already-running guest VM (reproducer ran as UID 1000); no host capabilities, KVM ioctls, or guest root are needed beyond what any cloud VM tenant or compromised guest process already has.\nUI:N - No victim interaction is required once the attacker can run code in a KVM guest with a datamatch ioeventfd configured, which is the default virtio/QEMU setup.\nS:C - The vulnerable component is the host kernel KVM subsystem, but exploitation is initiated from a guest VM and causes a host kernel BUG/oops, crossing the hypervisor security boundary.\nC:N - The failure mode is an explicit BUG_ON() alignment check before any datamatch comparison; there is no out-of-bounds read, use-after-free, or other memory corruption that could disclose host data.\nI:N - The bug triggers a deliberate kernel BUG and does not corrupt or modify host memory; it is a crash-only denial-of-service with no integrity impact.\nA:H - A guest-triggered BUG_ON() in ioeventfd_write() causes a host kernel oops/panic, denying availability of the entire physical host and all co-resident VMs on multi-tenant KVM hypervisors."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "virt/kvm/eventfd.c"
                    ],
                    "versions": [
                        {
                            "version": "d34e6b175e61821026893ec5298cc8e7558df43a",
                            "lessThan": "2426c15c1395b7d5ccf1e5025ca898af7f3decb6",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "d34e6b175e61821026893ec5298cc8e7558df43a",
                            "lessThan": "4186c850789906b875a1d263377a4d37c078e317",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "d34e6b175e61821026893ec5298cc8e7558df43a",
                            "lessThan": "36ff44fb3d89960391e013fb9d91e23dbc48be47",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "d34e6b175e61821026893ec5298cc8e7558df43a",
                            "lessThan": "92fc631b69deb1c7d56aec2663003600799dcd75",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "d34e6b175e61821026893ec5298cc8e7558df43a",
                            "lessThan": "bf89e3738480d33cd515b4a18900e8443d40cd2e",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "d34e6b175e61821026893ec5298cc8e7558df43a",
                            "lessThan": "5da9b1a87ec7cc3489c27016313524769f12d9e0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "d34e6b175e61821026893ec5298cc8e7558df43a",
                            "lessThan": "5c87b47374682f69686068ad0a7779365a527b1c",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "d34e6b175e61821026893ec5298cc8e7558df43a",
                            "lessThan": "f1edbed787ba67988ed34e0132ca128b052b6ce8",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "virt/kvm/eventfd.c"
                    ],
                    "versions": [
                        {
                            "version": "2.6.32",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "2.6.32",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.261",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.212",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.178",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.145",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.95",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.38",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1.3",
                            "lessThanOrEqual": "7.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "5.10.261"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "5.15.212"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "6.1.178"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "6.6.145"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "6.12.95"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "6.18.38"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "7.1.3"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2.6.32",
                                    "versionEndExcluding": "7.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/2426c15c1395b7d5ccf1e5025ca898af7f3decb6"
                },
                {
                    "url": "https://git.kernel.org/stable/c/4186c850789906b875a1d263377a4d37c078e317"
                },
                {
                    "url": "https://git.kernel.org/stable/c/36ff44fb3d89960391e013fb9d91e23dbc48be47"
                },
                {
                    "url": "https://git.kernel.org/stable/c/92fc631b69deb1c7d56aec2663003600799dcd75"
                },
                {
                    "url": "https://git.kernel.org/stable/c/bf89e3738480d33cd515b4a18900e8443d40cd2e"
                },
                {
                    "url": "https://git.kernel.org/stable/c/5da9b1a87ec7cc3489c27016313524769f12d9e0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/5c87b47374682f69686068ad0a7779365a527b1c"
                },
                {
                    "url": "https://git.kernel.org/stable/c/f1edbed787ba67988ed34e0132ca128b052b6ce8"
                }
            ],
            "title": "KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}