Executive brief
A vulnerability was identified in the Linux kernel's virtualization component (KVM) specifically affecting how it handles memory for guest virtual machines. Due to a technical error in how memory offsets are calculated, the system could incorrectly validate memory boundaries when a virtual machine requests specific memory regions. While rated as low severity, this could theoretically allow for improper memory access or unexpected behavior within the virtualization environment.
Technical details
A vulnerability exists in the KVM guest_memfd component of the Linux kernel due to the use of signed 64-bit integers (loff_t) for offset and size calculations during memslot binding. In kvm_gmem_bind(), the sum of 'offset' and 'size' is checked against the inode size. Because these values were treated as signed, a sufficiently large positive offset could cause the sum to wrap into a negative value. Since the file size is always positive, the negative sum would pass the boundary check (offset + size > i_size_read(inode)), allowing an 'absurd' offset to be accepted. The fix involves treating these values as unsigned (uoff_t) to ensure correct overflow and boundary validation.
Affected products
- Linux Linux Kernel a7800aa80ea4 to eba85fee7fc6
Timeline
- 2026-06-02: disclosed: Initial patch submitted by Sean Christopherson
- 2026-06-03: patched: Patch committed to stable tree
- 2026-07-25: advisory: NVD publication date