Junglewise Threat Intelligence

CVE-2026-53345: Linux Kernel KVM memory leak during VM destruction in mark_page_dirty_in_slot

CVE-2026-53345 · Severity: info · CVSS 0 · Published 2026-07-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A technical issue was identified in the Linux Kernel's virtualization component (KVM) that could lead to memory leaks in specific virtual machine configurations, such as those using AMD SEV-ES. The issue involves how the system tracks changes to memory when a virtual machine is being shut down. While primarily a stability and resource management concern, it could impact the reliability of host systems running multiple secure virtual machines.

Technical details

A vulnerability in `virt/kvm/kvm_main.c` in the Linux kernel was identified where KVM would trigger a `WARN` (and potentially fail to clean up resources) when guest memory was marked dirty without an active vCPU context during VM destruction. In SEV-ES guests, KVM may maintain writable mappings across userspace exits; if the VM is destroyed before the next `KVM_RUN`, the subsequent unmapping triggers a false-positive warning because no vCPU is loaded. The fix modifies `mark_page_dirty_in_slot` to only trigger the warning if the VM's refcount (`kvm->users_count`) is non-zero, acknowledging that dirty ring tracking is irrelevant once userspace mappings are gone. This resolution prevents a memory leak in SEV-ES guest cleanup paths.

Affected products

  • Linux Linux Kernel virt/kvm/kvm_main.c

Timeline

  • 2026-05-29: patched: Initial patch authored by Sean Christopherson
  • 2026-07-01: advisory: CVE-2026-53345 published by NVD

References

Related threats