Executive brief
A vulnerability in the Linux kernel's virtualization component (KVM) could allow a guest virtual machine to interfere with the host or other virtual environments. Specifically, when using nested virtualization on AMD processors, the system may incorrectly handle certain memory state operations. This could lead to system instability, data corruption, or a complete service outage of the host server.
Technical details
A logic error in the Linux kernel's KVM nSVM implementation fails to consistently use the primary Virtual Machine Control Block (vmcb01) during VMLOAD/VMSAVE emulation. While a previous commit intended to standardize on vmcb01 for guest state, the emulation path was not updated. If an L2 guest executes these instructions and they are not intercepted by the L1 hypervisor, KVM mistakenly operates on vmcb02. This can result in incorrect guest state being loaded or saved, leading to potential privilege escalation from guest to host or denial of service. The fix ensures that emulation always targets vmcb01 as intended.
Affected products
- Linux Linux Kernel cc3ed80ae69f to 127ccae2c185f62e6ecb4bf24f9cb307e9b9c619
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat OpenShift Container Platform 4
Timeline
- 2026-05-06: disclosed
- 2026-01-14: patched: Initial fix in mainline kernel tree
- 2026-05-06: advisory
References
- https://git.kernel.org/stable/c/0004ecb798b30e90d7ebfe74efae2d9423315a64
- https://git.kernel.org/stable/c/10063e1251c1485034a018236080792ad083dcc5
- https://git.kernel.org/stable/c/127ccae2c185f62e6ecb4bf24f9cb307e9b9c619
- https://git.kernel.org/stable/c/3880e331b0b31d0d5d3702b124f6c93539cd478a
- https://git.kernel.org/stable/c/c3b7015000988ba35ecd5648f4b2283960f00543
- https://git.kernel.org/stable/c/d464cf1ed900d47c85393d40b00017b6adfc2e6c
- https://git.kernel.org/stable/c/fce2fd4a2ca05670a91015aacccf96a1c26268fd