Executive brief
A vulnerability in the Linux kernel's virtualization component (KVM) could allow a user on a guest virtual machine to cause a system crash or potentially gain unauthorized access to the host system. The issue occurs when the system incorrectly manages memory addresses during complex memory remapping operations. This could lead to a 'use-after-free' scenario where the system attempts to use memory that has already been released, resulting in instability or security breaches.
Technical details
A use-after-free vulnerability exists in the Linux kernel KVM x86 MMU's shadow paging implementation. The root cause is an incorrect assumption that the Guest Frame Number (GFN) for direct shadow pages always matches the expected range based on the shadow page's base GFN and index. If guest page tables are modified externally between VM entries, KVM may install a leaf SPTE with a GFN outside the tracked range. Consequently, when the associated kvm_mmu_page is zapped, the rmap entry is not found or removed. Subsequent rmap walks (e.g., during dirty logging or MMU invalidations) then dereference the already-freed kvm_mmu_page. The fix involves explicitly checking for GFN mismatches and zapping existing SPTEs when such a mismatch is detected.
Affected products
- Linux Linux Kernel All versions prior to the May 2026 patches
Timeline
- 2026-03-27: other: Related commit aad885e77496 referenced as similar issue
- 2026-05-05: patched: Initial fix authored by Sean Christopherson
- 2026-05-28: advisory: CVE-2026-46113 published by NVD
References
- https://git.kernel.org/stable/c/06c19c967b845b63172601fe459667d973b7e6b7
- https://git.kernel.org/stable/c/0cb2af2ea66ad8ff195c156ea690f11216285bdf
- https://git.kernel.org/stable/c/14d1e55dfd2cf4711bff164a6aaaddb783552134
- https://git.kernel.org/stable/c/488e386484ec8c0e558be6e156edf34ed9f4d5c8
- https://git.kernel.org/stable/c/738ec97b1855df6c08fe2369f798fa0b972e556b