Junglewise Threat Intelligence

CVE-2026-46071: Linux Kernel KVM nSVM state corruption in LBR virtualization

CVE-2026-46071 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A technical issue was identified in the Linux kernel's virtualization component (KVM) for AMD processors. The software was incorrectly modifying internal state tracking bits during virtual machine operations in a way that is not supported by the hardware architecture. While primarily a stability and correctness fix, it ensures that virtualized environments behave predictably and do not encounter unexpected errors during guest-to-host transitions.

Technical details

The vulnerability exists in the KVM nSVM (nested Secure Virtual Machine) implementation for AMD processors. The function `svm_copy_lbrs()` was unconditionally marking the VMCB_LBR (Last Branch Record) field as dirty in the destination VMCB. When `nested_svm_vmexit()` used this function to copy LBR data to `vmcb12`, it resulted in clearing clean bits in a manner not architecturally defined for `vmcb12`. This could lead to inconsistent state management during nested virtualization transitions. The fix involves moving the `vmcb_mark_dirty()` call to the appropriate callers and omitting it when the destination is `vmcb12`.

Affected products

  • Linux Linux Kernel nSVM with LBR virtualization enabled

Timeline

  • 2026-03-03: patched: Initial patch authored by Yosry Ahmed
  • 2026-05-27: advisory: NVD publication date

References

Related threats