CVE-2026-74607
Race in Linux KVM SEV owner/mirror handling can corrupt lists and enable guest-to-host compromise
Is CVE-2026-74607 being exploited?
Not confirmed. CVE-2026-74607 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.13% probability of exploitation in the next 30 days.
How severe is CVE-2026-74607?
CVE-2026-74607 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74607?
Yes. A fix has been recorded for CVE-2026-74607. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74607 affect?
CVE-2026-74607 affects Linux kernel (KVM SVM/SEV), KVM-enabled hosts, VMs using AMD SEV. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74607?
Apply vendor/kernel security updates that include the KVM SEV fix and reboot hosts.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Guest-to-host race condition in KVM SEV can corrupt kernel data structures, allowing VM escape, kernel-level code execution or DoS.
Patch when possible
- affected>= b2125513dfc0dd0ec5a9605138a3c356592cfb73 and < 7943ec3a6d0e7e0a2eb4943300bce089ac3e8c3e
- affected>= b2125513dfc0dd0ec5a9605138a3c356592cfb73 and < 28afde1edbd8b20058cbf4d75fb57876471ec334
- affected>= b2125513dfc0dd0ec5a9605138a3c356592cfb73 and < 328ab4fabe05af004d886659f8744076e320ddce
- affected>= b2125513dfc0dd0ec5a9605138a3c356592cfb73 and < 47976eaaf0a4eb46dade48b3246779090db9e3ec
- affected>= b2125513dfc0dd0ec5a9605138a3c356592cfb73 and < d728baba0f20e49439fc7831bf3e4e7dee82161a
- affected>= b2125513dfc0dd0ec5a9605138a3c356592cfb73 and < 1d78d33275ef2a16c6d080910b291d0a97a0e613
- affected5.18
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.