Junglewise Threat Intelligence

CVE-2026-23401: Linux Kernel KVM stale SPTE in x86 MMU

CVE-2026-23401 · Severity: medium · CVSS 5.5 · Published 2026-04-01

Technologies: Linux Kernel. Vendors: Red Hat, Linux.

Executive brief

A vulnerability in the Linux kernel's virtualization component (KVM) could allow a local attacker to cause a system crash or instability. The issue occurs when the system fails to properly clear old memory mapping entries when switching a memory region to an emulated hardware interface. This can lead to a kernel warning or 'use-after-free' condition, potentially disrupting virtual machine operations and host stability.

Technical details

A vulnerability exists in the Linux kernel x86 MMU implementation within KVM. The root cause is a logic error in `mmu_set_spte` where the kernel fails to drop/zap an existing shadow-present SPTE when installing an emulated MMIO SPTE. This occurs when host userspace modifies a shadowed guest page table entry (gPTE) to switch from a memslot to emulated MMIO, and the guest subsequently triggers a page fault. Because the old SPTE is not cleared, it can lead to a stale state or a use-after-free (CWE-416) condition. An attacker with local access to the host or control over host userspace processes managing VMs could exploit this to trigger kernel warnings or crashes. Patches have been released across multiple stable kernel branches (e.g., 6.x, 7.x).

Affected products

  • Linux Linux Kernel 7.0.0-rc2; versions prior to 6.13.x
  • Red Hat Red Hat Enterprise Linux 10.0
  • Red Hat Red Hat Enterprise Linux 9.0

Timeline

  • 2026-03-31: patched: Initial patch authored by Sean Christopherson
  • 2026-04-01: disclosed: CVE published

References

Related threats