Executive brief
A technical issue was identified in the Linux kernel's virtualization component (KVM) for AMD processors. The software was incorrectly modifying internal state tracking bits during virtual machine operations in a way that is not supported by the hardware architecture. While primarily a stability and correctness fix, it ensures that virtualized environments behave predictably and do not encounter unexpected errors during guest-to-host transitions.
Technical details
The vulnerability exists in the KVM nSVM (nested Secure Virtual Machine) implementation for AMD processors. The function `svm_copy_lbrs()` was unconditionally marking the VMCB_LBR (Last Branch Record) field as dirty in the destination VMCB. When `nested_svm_vmexit()` used this function to copy LBR data to `vmcb12`, it resulted in clearing clean bits in a manner not architecturally defined for `vmcb12`. This could lead to inconsistent state management during nested virtualization transitions. The fix involves moving the `vmcb_mark_dirty()` call to the appropriate callers and omitting it when the destination is `vmcb12`.
Affected products
- Linux Linux Kernel nSVM with LBR virtualization enabled
Timeline
- 2026-03-03: patched: Initial patch authored by Yosry Ahmed
- 2026-05-27: advisory: NVD publication date