CVE-2020-27152 affects the Linux kernel's KVM hypervisor and can let a malicious or untrusted guest trigger a host-kernel stack overflow. The flaw arises during interrupt processing when lazy IOAPIC updates incorrectly set IRQ state, producing an infinite loop that exhausts the host stack and crashes the kernel.
The issue creates a guest-to-host denial-of-service risk for systems running KVM workloads, potentially disrupting every virtual machine on an affected host. Upstream Linux addressed the vulnerability in commit 77377064c3a94911339f13ce113b3abf265e06da; organizations should apply kernel updates incorporating that fix and prioritize KVM hosts exposed to untrusted tenants or guest administrators.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Prasad J. Pandit of Red Hat Product Security disclosed CVE-2020-27152, a KVM lazy-IOAPIC interrupt-processing flaw that can let an untrusted guest trigger an infinite loop and crash the host kernel. MITRE assigned the CVE identifier, and an upstream fix was made available in Linux kernel commit 77377064c3a94911339f13ce113b3abf265e06da.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
openwall.com
Open sourcecveform.mitre.org
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.