Memory Access Vulnerability in KVM Module for Linux Kernel
CVE-2026-63807
What is CVE-2026-63807?
This vulnerability in the KVM module of the Linux kernel arises during the hugepage recovery process in the shadow memory management unit (MMU). When a hugepage is being recovered, the system fails to verify that the base guest frame number (gfn) lies within the bounds of the target memory slot prior to querying the maximum mapping level. As a result, this inconsistency can lead to an out-of-bounds memory access, which typically results in a fault error due to the incorrect memory location being accessed. If a guest system attempts to create a hugepage mapping extending beyond a memory slot, it may link to an invalid shadow page, escalating the risk of systemic instability and potential exploits.
Affected Version(s)
Linux 9eba50f8d7fcb61774f160890f98239fa3ab68a6 < 7b52008023b7facf40fba3ebe92449bda8ea53b9
Linux 9eba50f8d7fcb61774f160890f98239fa3ab68a6 < 5cab1c989f938f5e1b9a0de66486f1fc2c28479b
Linux 9eba50f8d7fcb61774f160890f98239fa3ab68a6 < 48b91ed7e22bb82571c34f8b80b6ecdc90a6fab8