Description
A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked SMRAM, bypassing chipset D_LCK protection and injecting code into System Management Mode memory.
Published: 2026-09-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to System Management Mode via SMRAM injection
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in QEMU’s VAPIC setup hypercall allows a privileged guest to position a writable RAM alias outside the intended option‑ROM window, overwriting locked System Management Mode RAM. The injected code runs with full System Management Mode privileges, giving the attacker complete control over the host system. The weakness is a classic buffer‑overrun/validation issue (CWE‑787), permitting unauthorized memory writes that compromise system integrity and confidentiality.

Affected Systems

Red Hat Enterprise Linux 10, 6, 7, 8, 9, Red Hat Enterprise Linux for NVIDIA 26, Red Hat OpenShift Container Platform 4, and Red Hat OpenStack Platform 13 (Queens) that rely on QEMU for virtual machine execution. No specific version numbers are listed, so all installations using the affected QEMU build should be considered vulnerable.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity; the EPSS score of < 1% indicates a very low exploitation probability and the vulnerability is not in the CISA KEV catalog, suggesting no publicly known exploits yet. The attack requires a privileged guest on a Q35/KVM machine, implying that the attacker must run a virtual machine with elevated rights on the host. While the exploit path is not trivial, the potential impact of escaping SMRAM means that the risk is significant for environments that grant VM hypervisor privileges.

Generated by OpenCVE AI on September 21, 2026 at 12:28 UTC.

Remediation

Vendor Workaround

The VAPIC TPR optimization can be disabled by preventing the kvmvapic option ROM from loading. When using libvirt, set the following in the guest's domain XML: ``` <features> <apic/> <hyperv> <vapic state='off'/> </hyperv> </features> ``` When using QEMU directly, pass `-global kvmvapic.rom=off` on the command line. This optimization is only used by 32-bit Windows guests for MMIO-based TPR register access. Linux guests, 64-bit Windows guests, and any guest using x2APIC or MSR-based TPR access are unaffected by disabling it.


OpenCVE Recommended Actions

  • Apply updated QEMU and Red Enterprise Linux kernel that contain the fix for the VAPIC ROM alias issue.
  • If using libvirt, modify the guest’s domain XML to disable the kvmvapic option ROM: add <features><apic/><hyperv><vapic state='off'/></hyperv></features>.
  • If using QEMU directly, start the guest with the option -global kvmvapic.rom=off to prevent loading the VAPIC TPR optimization.

Generated by OpenCVE AI on September 21, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Qemu
Qemu qemu
Redhat enterprise Linux For Nvidia 26
Redhat openshift Container Platform
Redhat openstack Platform
Vendors & Products Qemu
Qemu qemu
Redhat enterprise Linux For Nvidia 26
Redhat openshift Container Platform
Redhat openstack Platform

Fri, 18 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked SMRAM, bypassing chipset D_LCK protection and injecting code into System Management Mode memory.
Title Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram
First Time appeared Redhat
Redhat enterprise Linux
Redhat enterprise Linux Nvidia
Redhat openshift
Redhat openstack
Weaknesses CWE-787
CPEs cpe:/a:redhat:enterprise_linux_nvidia:
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openstack:13
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat enterprise Linux Nvidia
Redhat openshift
Redhat openstack
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Qemu Qemu
Redhat Enterprise Linux Enterprise Linux For Nvidia 26 Enterprise Linux Nvidia Openshift Openshift Container Platform Openstack Openstack Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-21T11:32:47.295Z

Reserved: 2026-08-27T09:01:09.972Z

Link: CVE-2026-81627

cve-icon Vulnrichment

Updated: 2026-09-18T15:06:55.575Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T11:17:18.490

Modified: 2026-09-21T12:17:20.197

Link: CVE-2026-81627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T12:30:14Z

Weaknesses