Sploitus

CVE-2026-72285

No indexed exploits for CVE-2026-72285 yet

In the Linux kernel, the following vulnerability has been resolved: KVM: TDX: Reject concurrent change to CPUID entry count Reject KVM_TDX_INIT_VM if userspace changes cpuid.nent between the initial read and the subsequent copy of the initialization data. tdx_td_init() first reads user_data->cpuid.nent to size the flexible kvm_tdx_init_vm copy. The copied structure also contains cpuid.nent, and that field can differ from the value used to size the allocation if userspace modifies the input concurrently. setup_tdparams_cpuids() later passes init_vm->cpuid.nent to kvm_find_cpuid_entry2(), which uses it as the array bound for the copied entries. Require the copied count to match the value used to size the allocation so that CPUID parsing cannot access beyond the entries actually copied.

CVSS 3.1
7.8 HIGH
EPSS
0.2% (5th percentile)
NVD status
Received
Published
2026-08-15
CVE-2026-72285 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-72285 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-72285 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.