Partially initialized VP use via irqfd race
Published Sep 4, 2026 · Updated Sep 4, 2026
A race condition in the Linux kernel mshv driver allows local users to trigger use of partially initialized virtual-processor fields through irqfd. mshv_partition_ioctl_create_vp publishes a VP pointer before initialization stores are guaranteed visible, while mshv_try_assert_irq_fast reads it locklessly. Exploitation requires access to MSHV_CREATE_VP and MSHV_IRQFD, concurrent operations for the same VP index, and a weakly ordered architecture; the published record specifies no consequence beyond use of partially initialized fields.
Summary
What happened
A race condition in the Linux kernel mshv driver allows local users to trigger use of partially initialized virtual-processor fields through irqfd. mshv_partition_ioctl_create_vp publishes a VP pointer before initialization stores are guaranteed visible, while mshv_try_assert_irq_fast reads it locklessly. Exploitation requires access to MSHV_CREATE_VP and MSHV_IRQFD, concurrent operations for the same VP index, and a weakly ordered architecture; the published record specifies no consequence beyond use of partially initialized fields.
The record
- CVE
- CVE-2026-80895
- Published
- Sep 4, 2026
- Updated
- Sep 4, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- Unavailable
- Attack vector
- local
- Privileges
- Unavailable
Timeline
How it unfolded
- Sep 4, 2026CVE publishedPublication date reported by the CVE source.
- Sep 4, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=6.15
- Affected versionversion=621191d709b14882270dfd8ea5d7d6cdfebe2c35 <062aa5dcc49a9ad96726a80c2a0ab0a1233bc2b9
- Affected versionversion=621191d709b14882270dfd8ea5d7d6cdfebe2c35 <b098dc869219c15dc49bf9cf63fb5fc1481d3373
- Affected versionversion=621191d709b14882270dfd8ea5d7d6cdfebe2c35 <eba2bf5daa7933f94c53ebbbf0f567d4274716df
What conditions does exploitation require?
What is affected?
Published CVSS scores
No CVSS assessment is available in this record.
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
No sourced classifications are available.
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo