Junglewise Threat Intelligence

CVE-2026-64247: Linux Kernel KVM out-of-bounds read in Hyper-V sparse bank querying

CVE-2026-64247 · Severity: info · CVSS 0 · Published 2026-07-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's virtualization component (KVM) when running with Hyper-V features enabled. An attacker or a malicious guest virtual machine could potentially trigger an out-of-bounds memory read on the host system. This could lead to system instability or a crash, impacting the availability of the virtualization host and other hosted services.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel's KVM Hyper-V implementation within the 'hv_is_vp_in_sparse_set' function. When handling paravirtual TLB flushes for L2 guests, the VP ID is copied directly from the enlightened VMCS without sufficient bounds checking. Because the TLFS (Top Level Functional Specification) limits sparse banks to 64 banks of 64 vCPUs (4096 total), an unvalidated VP ID can exceed this range, causing KVM to read memory outside the intended bank mask. This was detected as a use-after-free/out-of-bounds read by KASAN. The issue is resolved by explicitly bounding the bank index against 'HV_MAX_SPARSE_VCPU_BANKS'.

Affected products

  • Linux Linux Kernel 7.1.0-rc2

Timeline

  • 2026-06-06: disclosed: Initial patch authored
  • 2026-07-24: advisory: CVE published to NVD dataset

References

Related threats