CVE-2024-26976
Linux Linux, linux_kernel, linux kernel
In the Linux kernel, the following vulnerability has been resolved: KVM: Always flush async #PF workqueue when vCPU is being destroyed Always flush the per-vCPU async #PF workqueue when a vCPU is clearing its completion queue, e.g. when a VM and all its vCPUs is being destroyed. KVM must ensure that none of its workqueue callbacks is running when the last reference to the KVM _module_ is put. Gifting a reference to the associated VM prevents the workqueue callback from dereferencing freed vCPU/VM memory, but does not prevent the KVM module from being unloaded before the callback completes....
- CVSS
- 7.8
- EPSS
- 0.26% 17.7% percentile
- CISA KEV
- Not listed
- Published
- 2024.05.01