Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-81627

CVE-2026-81627: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh8.2

    High [CVE-2026-81627] Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram

    CVE-2026-81627Source published Source updated

    A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked SMRAM, bypassing chipset D_LCK protection and injecting code into System Management Mode memory. This flaw allows a privileged guest to bypass SMRAM locking on Q35 machine types by placing the VAPIC writable ROM alias outside the option-ROM window. While the kvmvapic TPR optimization is normally used only by 32-bit Windows guests, any privileged guest can deliberately invoke the VAPIC setup hypercall to trigger the vulnerable code path. Exploitation requires guest root access and KVM acceleration. Red Hat severity: Important — CVSS 8.2…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 7
    • Red Hat Enterprise Linux 8
    • Red Hat Enterprise Linux 9

    4 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • The VAPIC TPR optimization can be disabled by preventing the kvmvapic option ROM from loading. When using libvirt, set the following in the guest's domain XML: ``` <features> <apic/> <hyperv> <vapic state='off'/> </hyperv> </features> ``` When using QEMU directly, pass `-global kvmvapic.rom=off` on the command line. This optimization is only used by 32-bit Windows guests for MMIO-based TPR register access. Linux guests, 64-bit Windows guests, and any guest using x2APIC or MSR-based TPR access are unaffected by disabling it.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery