Executive brief
A vulnerability was identified in the Linux kernel's virtualization component (KVM) when running with Hyper-V features enabled. An attacker or a malicious guest virtual machine could potentially trigger an out-of-bounds memory read on the host system. This could lead to system instability or a crash, impacting the availability of the virtualization host and other hosted services.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel's KVM Hyper-V implementation within the 'hv_is_vp_in_sparse_set' function. When handling paravirtual TLB flushes for L2 guests, the VP ID is copied directly from the enlightened VMCS without sufficient bounds checking. Because the TLFS (Top Level Functional Specification) limits sparse banks to 64 banks of 64 vCPUs (4096 total), an unvalidated VP ID can exceed this range, causing KVM to read memory outside the intended bank mask. This was detected as a use-after-free/out-of-bounds read by KASAN. The issue is resolved by explicitly bounding the bank index against 'HV_MAX_SPARSE_VCPU_BANKS'.
Affected products
- Linux Linux Kernel 7.1.0-rc2
Timeline
- 2026-06-06: disclosed: Initial patch authored
- 2026-07-24: advisory: CVE published to NVD dataset
References
- https://git.kernel.org/stable/c/4721f8160f17554b003e8928bb61e6c9b2fe92a3
- https://git.kernel.org/stable/c/83c2f52c6a78b1590034e955cff3fe0b052fe4ae
- https://git.kernel.org/stable/c/d18756b12aab30d07794446445c93112e5c69a2e
- https://git.kernel.org/stable/c/e36095d8d922bb26ce860231aacf0cd14edea07c
- https://git.kernel.org/stable/c/f636cf6a1e7b7f40d48d8d08bd5f152aa61dd130