{"schema_version":"1.7.5","id":"CVE-2026-63806","published":"2026-07-19T12:02:10.209Z","modified":"2026-07-25T04:14:34.834708670Z","related":["openSUSE-SU-2026:11339-1"],"summary":"KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()\n\nDrop a BUG_ON() that has been reachable since it was first added, way back\nin 2009, and instead use get_unaligned() to perform potentially-unaligned\naccesses.\n\nFor a given store, KVM x86's emulator tracks the entire value in the\ndestination operand, x86_emulate_ctxt.dst.  If the destination is memory,\nand the target splits multiple pages and/or is emulated MMIO, then KVM\nhandles each fragment independently.  E.g. on a page split starting at page\noffset 0xffc, KVM writes 4 bytes to the first page, then the remaining\nbytes to the second page, using ctxt->dst as the source for both (with\nappropriate offsets).\n\nIf the destination splits a page *and* hits emulated MMIO on the second\npage, then KVM will complete the write to the first page, then emulate the\nMMIO access to the second page.  If there is a datamatch-enabled ioeventfd\nat offset 0 of the second page, then KVM will process the remainder of the\nstore as a potential ioeventfd signal.\n\nPutting it all together, if the guest emits a store that splits a page\nstarting at page offset N, and the second page has a datamatch-enabled\nioeventfd at offset 0, then KVM will check for datamatch using\n&dst.valptr[N] as the source.  Due to dst (and thus dst.valptr) being\n32-byte aligned, if N is not aligned to @len, the BUG_ON() fires.\n\nE.g. with a 16-byte store at page offset 0xffc, to an ioeventfd of len 8,\nall initial checks in ioeventfd_in_range() will succeed, and the BUG_ON()\nfires due to @val being 4-byte aligned, but not 8-byte aligned.\n\n  ------------[ cut here ]------------\n  kernel BUG at arch/x86/kvm/../../../virt/kvm/eventfd.c:783!\n  Oops: invalid opcode: 0000 [#1] SMP\n  CPU: 0 UID: 1000 PID: 615 Comm: repro Not tainted 7.1.0-rc2-ff238429d1ea #365 PREEMPT\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n  RIP: 0010:ioeventfd_write+0x6c/0x70 [kvm]\n  Call Trace:\n   <TASK>\n   __kvm_io_bus_write+0x85/0xb0 [kvm]\n   kvm_io_bus_write+0x53/0x80 [kvm]\n   vcpu_mmio_write+0x66/0xf0 [kvm]\n   emulator_read_write_onepage+0x12a/0x540 [kvm]\n   emulator_read_write+0x109/0x2b0 [kvm]\n   x86_emulate_insn+0x4f8/0xfb0 [kvm]\n   x86_emulate_instruction+0x181/0x790 [kvm]\n   kvm_mmu_page_fault+0x313/0x630 [kvm]\n   vmx_handle_exit+0x18a/0x590 [kvm_intel]\n   kvm_arch_vcpu_ioctl_run+0xc81/0x1c90 [kvm]\n   kvm_vcpu_ioctl+0x2d5/0x970 [kvm]\n   __x64_sys_ioctl+0x8a/0xd0\n   do_syscall_64+0xb7/0x890\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n  RIP: 0033:0x7f19c931a9bf\n   </TASK>\n  Modules linked in: kvm_intel kvm irqbypass\n  ---[ end trace 0000000000000000 ]---\n\nIn a perfect world, the fix would be to simply delete the BUG_ON(), as KVM\nx86 doesn't perform alignment checks on \"normal\" memory accesses at CPL0.\nSadly, C99 ruins all the fun; while the x86 architecture plays nice,\ndereferencing an unaligned pointer directly is undefined behavior in C,\ne.g. triggers splats when running with CONFIG_UBSAN_ALIGNMENT=y.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"d34e6b175e61821026893ec5298cc8e7558df43a"},{"fixed":"2426c15c1395b7d5ccf1e5025ca898af7f3decb6"},{"fixed":"4186c850789906b875a1d263377a4d37c078e317"},{"fixed":"36ff44fb3d89960391e013fb9d91e23dbc48be47"},{"fixed":"92fc631b69deb1c7d56aec2663003600799dcd75"},{"fixed":"bf89e3738480d33cd515b4a18900e8443d40cd2e"},{"fixed":"5da9b1a87ec7cc3489c27016313524769f12d9e0"},{"fixed":"5c87b47374682f69686068ad0a7779365a527b1c"},{"fixed":"f1edbed787ba67988ed34e0132ca128b052b6ce8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63806.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.32"},{"fixed":"5.10.261"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.95"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.38"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.3"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63806.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2426c15c1395b7d5ccf1e5025ca898af7f3decb6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/36ff44fb3d89960391e013fb9d91e23dbc48be47"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4186c850789906b875a1d263377a4d37c078e317"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5c87b47374682f69686068ad0a7779365a527b1c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5da9b1a87ec7cc3489c27016313524769f12d9e0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/92fc631b69deb1c7d56aec2663003600799dcd75"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bf89e3738480d33cd515b4a18900e8443d40cd2e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f1edbed787ba67988ed34e0132ca128b052b6ce8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63806.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63806"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63806.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"}]}