{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs  Ignore KVM's internal \"service pending PV EOI\" request if the vCPU has disabled PV EOIs since the request was made.  Asserting that PV EOIs are enabled can fail if reading guest memory in pv_eoi_get_user() fails, i.e. if pv_eoi_test_and_clr_pending() bails early, *and* the vCPU also disables PV EOIs.    kernel BUG at arch/x86/kvm/lapic.c:3338!   Oops: invalid opcode: 0000 [#1] SMP   CPU: 4 UID: 1000 PID: 890 Comm: pv_eoi_test Not tainted 7.0.0-d585aa5894d8-vm #337 PREEMPT   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015   RIP: 0010:kvm_lapic_sync_from_vapic+0x12b/0x140 [kvm]   Call Trace:    \u003cTASK\u003e    kvm_arch_vcpu_ioctl_run+0x1075/0x1c30 [kvm]    kvm_vcpu_ioctl+0x2d5/0x980 [kvm]    __x64_sys_ioctl+0x8a/0xd0    do_syscall_64+0xb5/0xb40    entry_SYSCALL_64_after_hwframe+0x4b/0x53    \u003c/TASK\u003e   Modules linked in: kvm_intel kvm irqbypass   ---[ end trace 0000000000000000 ]---",
  "id": "DEBIAN-CVE-2026-72284",
  "modified": "2026-09-14T16:47:48.787452869Z",
  "published": "2026-08-15T06:21:59.240Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-72284"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-72284"
  ]
}