Out-of-Bounds Read Vulnerability in Linux Kernel's KVM Hypervisor Product
CVE-2026-64247

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-64247?

A vulnerability in the Linux kernel's KVM module could lead to an out-of-bounds read condition when validating VP IDs against sparse bank sets. By neglecting to impose a bounds check, a VP ID may exceed defined limits, which can result in unnecessary TLB flush operations for L2 vCPUs, ultimately impacting performance and stability. Ensuring that bounds are strictly adhered to is essential to mitigate risks associated with this potential memory access issue.

Affected Version(s)

Linux c58a318f6090efe06e6702b8882e2026f44f620e

Linux c58a318f6090efe06e6702b8882e2026f44f620e < 83c2f52c6a78b1590034e955cff3fe0b052fe4ae

Linux c58a318f6090efe06e6702b8882e2026f44f620e

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.