Executive brief
A vulnerability exists in the Linux kernel's virtualization component (KVM) that could allow a local attacker to compromise the host system. The issue occurs when the system handles specific memory operations that span across different memory pages, leading to a memory error. This could potentially allow an attacker to gain unauthorized access to sensitive data or take control of the underlying server.
Technical details
A use-after-free vulnerability exists in the Linux kernel KVM x86 emulator when servicing emulated MMIO writes that split across page boundaries. When a write operation spans two MMIO pages, KVM splits the request into fragments. If the emulator uses an on-stack local variable as the source for the write, a second userspace exit (KVM_RUN) may reference that variable after it has been freed from the stack. This is particularly exploitable if a separate task performs the second KVM_RUN, accessing the stale stack memory. The fix involves copying small write values (8 bytes or less) into a persistent scratch field within the MMIO fragment instead of maintaining a pointer to the original stack-based source.
Affected products
- Linux Linux Kernel 6.13 to 6.18.24, 6.19 to 6.19.14
Timeline
- 2026-04-24: advisory: CVE-2026-31588 published
- 2026-06-01: patched: Fix committed to stable tree
References
- https://git.kernel.org/stable/c/019d0bd32b9a4646ba35d904907452039e2db700
- https://git.kernel.org/stable/c/0b16e69d17d8c35c5c9d5918bf596c75a44655d3
- https://git.kernel.org/stable/c/22d2ff69d487a32a8b88f9c970120fc2daa08a77
- https://git.kernel.org/stable/c/2b83d91e9ae92fe1258d7040a32430bbb3bb7d6e
- https://git.kernel.org/stable/c/3a7b6d75c8f85b09dea893f64a85a356bcf6c3fe
- https://git.kernel.org/stable/c/4569c66dd9e94a22cd0796b6514a8b25ffff16a1
- https://git.kernel.org/stable/c/52570e73d48f1c73836d37e594667117b4c2a5a8