Linux Kernel KVM Xen Hypercall Poll Cleanup Vulnerability

Vulnerability

A vulnerability in the Linux kernel's KVM component for Xen virtualization has been addressed. The issue arose in the emulation of the Xen 'schedop poll' hypercall, specifically when a virtual machine (VM) polled the host for more than one event channel. The 'schedop_poll' function allocated memory for multiple event channels, but the error handling did not properly manage the cleanup, leading to potential memory management issues.

Impact

The vulnerability could have caused improper memory handling, potentially leading to memory leaks or other memory-related issues.

Added: Jul 28, 2025, 1:24 PM
Updated: Jul 28, 2025, 1:24 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.