Executive brief
The Linux kernel's KVM hypervisor fails to properly release pinned memory pages when a nested virtual machine (L2) fails to enter due to invalid guest state during VMLAUNCH or VMRESUME operations. If a guest hypervisor (L1) retries these operations, additional memory pages remain pinned, gradually exhausting available memory and degrading system performance or availability.
Technical details
This is a resource leak vulnerability in the KVM nVMX (nested virtualization for AMD-V) implementation. The vulnerable code path in arch/x86/kvm/vmx/nested.c fails to call nested_put_vmcs12_pages() when synthesizing a nested VM-Exit due to invalid guest state, whereas the normal VM-Exit path via nested_vmx_vmexit() correctly releases these resources. An attacker with the ability to control a nested VM could repeatedly trigger invalid guest state conditions to exhaust pinned memory pages. The fix adds the missing nested_put_vmcs12_pages() call in the error path. This affects Linux kernel versions with nested virtualization support.
Affected products
- Linux Linux kernel multiple versions with nested virtualization support
Timeline
- 2026-07-14: disclosed
- 2026-07-15: patched