Junglewise Threat Intelligence

CVE-2025-68810: Linux Kernel KVM use-after-free in guest_memfd toggling

CVE-2025-68810 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux Kernel's virtualization component (KVM) could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system incorrectly handles memory regions used by virtual machines, leading to a memory corruption state known as a use-after-free. This affects servers running virtualized workloads where an attacker has local access to the host operating system.

Technical details

A use-after-free vulnerability exists in the Linux kernel KVM (Kernel-based Virtual Machine) subsystem due to improper handling of the KVM_MEM_GUEST_MEMFD flag. While KVM correctly prevents enabling this flag on existing memslots, it failed to prevent clearing the flag on memslots initially created with a guest_memfd binding. When the flag is cleared, KVM does not properly unbind from the guest_memfd instance, leading to a slab-use-after-free in kvm_gmem_release during file descriptor release or task exit. This can be triggered via the KVM_SET_USER_MEMORY_REGION ioctl. The fix involves rejecting any attempts to change the KVM_MEM_GUEST_MEMFD flag on existing memslots. Patches are available in stable kernel branches 6.12.64, 6.18.3, and 6.19.

Affected products

  • Linux Linux 6.8 to 6.12.63, 6.18.2

Timeline

  • 2025-12-01: other: Patch authored
  • 2026-01-13: disclosed: CVE published

References