Linux Kernel Vulnerability Affecting KVM's AVIC Functionality
CVE-2026-43483
What is CVE-2026-43483?
A vulnerability has been identified within the Linux kernel that affects the Kernel-based Virtual Machine (KVM) functionality, particularly its Advanced Virtual Interrupt Controller (AVIC). The flaw arises from a failure to properly manage the CR8 write interception when toggling AVIC activation, leading to potential discrepancies during virtual machine operations. If KVM emulates the INIT=>WFS sequence while AVIC is deactivated, the CR8 interception remains enabled, causing persistent behavior that may severely degrade performance. This bug can compound with a previously identified issue regarding TPR synchronization, resulting in Windows guests operating with out-of-sync TPR, which poses a significant risk to system integrity and function. VMX setups are unaffected due to specific handling of TPR_THRESHOLD when Virtual Interrupt Delivery is active.
Affected Version(s)
Linux 3bbf3565f48ce3999b5a12cde946f81bd4475312
Linux 3bbf3565f48ce3999b5a12cde946f81bd4475312 < 816fa1dfae4532e851b1fe6b2434c753ecbd86c7
Linux 3bbf3565f48ce3999b5a12cde946f81bd4475312 < 01651e7751edbbc0fb4598f8367a3dabcfc8c182