Junglewise Threat Intelligence

CVE-2026-64284: Linux Kernel KVM missing vendor exit handler in x86 fastpath

CVE-2026-64284 · Severity: info · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's virtualization component (KVM) could allow guest virtual machines to bypass certain memory tracking mechanisms. Specifically, when a virtual machine exits to the host system, it may fail to properly record changes made to memory. This could lead to data inconsistencies or failures in backup and migration processes that rely on accurate tracking of modified data.

Technical details

A vulnerability in KVM's x86 implementation occurs because fastpath userspace exits were handled before vendor-specific operations (VMX/SVM) could execute. In VMX environments, this prevents the flushing of the Page Modification Logging (PML) buffer prior to userspace gaining control of the vCPU. Consequently, memory writes performed during the final KVM_RUN may not be correctly flagged as dirty. This issue was resolved by moving fastpath userspace exit handling into the vendor-specific code (svm.c and vmx.c), ensuring necessary cleanup like PML flushing occurs. The fix is available in various stable kernel branches including 6.12.y and 6.18.y.

Affected products

  • Linux Linux 6.12, 6.12.96, 6.18.39, 7.1.4

Timeline

  • 2026-07-25: disclosed
  • 2026-07-25: advisory

References