ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability
The Linux kernel KVM IOAPIC has a use-after-free (CVSS 8.2) allowing local privilege escalation, but exploitation requires high-privileged code execution first.
ZDI-26-608 describes a use-after-free vulnerability in the Linux kernel's KVM IOAPIC component, with a CVSS score of 8.2. An attacker must first obtain the ability to execute high-privileged code on the target system, which limits the practical impact of the privilege escalation. The advisory text does not list an assigned CVE identifier.
SonicWall security advisory (AV26-884)
Canada's Cyber Centre issued advisory AV26-884 warning that SonicWall Network Security Manager On-Prem 4.3.0 and earlier are affected by multiple vulnerabilities.
The Canadian Centre for Cyber Security published advisory AV26-884 on September 4, 2026, flagging SonicWall Network Security Manager (NSM) On-Prem across VMware, Hyper-V, Azure, and KVM deployments, versions 4.3.0 and earlier, as affected by multiple vulnerabilities. The advisory does not list CVE identifiers, exploit details, or in-the-wild exploitation. Administrators are encouraged to review the referenced links and apply updates as they become available.