Junglewise Threat Intelligence

CVE-2026-68081: Linux kernel KVM nVMX memory leak on invalid guest state

CVE-2026-68081 · Severity: info · Published 2026-08-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's KVM hypervisor fails to properly release pinned memory pages when a nested virtual machine (L2) fails to enter due to invalid guest state during VMLAUNCH or VMRESUME operations. If a guest hypervisor (L1) retries these operations, additional memory pages remain pinned, gradually exhausting available memory and degrading system performance or availability.

Technical details

This is a resource leak vulnerability in the KVM nVMX (nested virtualization for AMD-V) implementation. The vulnerable code path in arch/x86/kvm/vmx/nested.c fails to call nested_put_vmcs12_pages() when synthesizing a nested VM-Exit due to invalid guest state, whereas the normal VM-Exit path via nested_vmx_vmexit() correctly releases these resources. An attacker with the ability to control a nested VM could repeatedly trigger invalid guest state conditions to exhaust pinned memory pages. The fix adds the missing nested_put_vmcs12_pages() call in the error path. This affects Linux kernel versions with nested virtualization support.

Affected products

  • Linux Linux kernel multiple versions with nested virtualization support

Timeline

  • 2026-07-14: disclosed
  • 2026-07-15: patched

References

Related threats