{"id":"CVE-2026-81627","published":"2026-09-18T11:17:18.490","lastModified":"2026-09-21T12:17:20.197","description":"A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked SMRAM, bypassing chipset D_LCK protection and injecting code into System Management Mode memory.","cvssScore":8.2,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-81627","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2536950","tags":[]},{"url":"https://gitlab.com/qemu-project/qemu/-/work_items/4206","tags":[]},{"url":"https://gitlab.com/qemu-project/qemu/-/work_items/4206","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}