Junglewise Threat Intelligence

CVE-2026-45987: Linux Kernel KVM nSVM denial of service via incorrect interrupt shadow sync

CVE-2026-45987 · Severity: info · CVSS 4.7 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's virtualization component (KVM) for AMD processors could cause virtual machines to stop responding. When a virtual machine is saved and then restored in a specific sequence, the system fails to correctly track 'interrupt shadows,' which are brief periods where hardware interrupts are blocked. This can lead to a situation where a virtual processor hangs indefinitely, causing a denial of service for that specific virtual machine.

Technical details

A flaw exists in the KVM nSVM (Nested Secure Virtual Machine) implementation for AMD processors. The function `nested_sync_control_from_vmcb02()` fails to synchronize the `int_state` field (specifically the `SVM_INTERRUPT_SHADOW_MASK` bit) from the active VMCB (vmcb02) to the cached control block (vmcb12). If `KVM_SET_VCPU_EVENTS` is called before `KVM_SET_NESTED_STATE` during a restore operation, the interrupt shadow is incorrectly applied to the L1 guest (vmcb01) instead of the L2 guest. This race condition in state restoration can lead to L2 vCPUs hanging, particularly if a wakeup interrupt is delivered before a HLT instruction that should have been protected by an interrupt shadow. The issue is resolved by ensuring `int_state` is properly synchronized to the cached vmcb12.

Affected products

  • Linux Linux Kernel nSVM component

Timeline

  • 2026-02-25: patched: Initial patch authored by Yosry Ahmed
  • 2026-05-27: disclosed: CVE-2026-45987 published

References

Related threats