Executive brief
A vulnerability in the Linux Kernel's virtualization component (KVM) could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system incorrectly handles memory regions used by virtual machines, leading to a memory corruption state known as a use-after-free. This affects servers running virtualized workloads where an attacker has local access to the host operating system.
Technical details
A use-after-free vulnerability exists in the Linux kernel KVM (Kernel-based Virtual Machine) subsystem due to improper handling of the KVM_MEM_GUEST_MEMFD flag. While KVM correctly prevents enabling this flag on existing memslots, it failed to prevent clearing the flag on memslots initially created with a guest_memfd binding. When the flag is cleared, KVM does not properly unbind from the guest_memfd instance, leading to a slab-use-after-free in kvm_gmem_release during file descriptor release or task exit. This can be triggered via the KVM_SET_USER_MEMORY_REGION ioctl. The fix involves rejecting any attempts to change the KVM_MEM_GUEST_MEMFD flag on existing memslots. Patches are available in stable kernel branches 6.12.64, 6.18.3, and 6.19.
Affected products
- Linux Linux 6.8 to 6.12.63, 6.18.2
Timeline
- 2025-12-01: other: Patch authored
- 2026-01-13: disclosed: CVE published