Vulnerability in Linux Kernel KVM Affects Memory Management
CVE-2026-64561

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-64561?

A flaw in the Linux kernel's KVM module relates to improper handling of invalid or obsolete root pages after making MMU pages available. The issue arises when the system fails to check for stale page faults, resulting in an attempt to map memory to an invalid root. This can occur when reclaiming shadow pages invalidates an in-use root. Consequently, child shadow pages may inherit this invalid status, violating the KVM's invariant that forbids invalid pages from populating the list of active MMU pages. This design flaw has existed since the inception of KVM's invalid root tracking but became significantly problematic with the introduction of stricter checks in Linux kernel version 5.9. A separate fix is expected to address the implications of inheriting the invalid role during child shadow page creation.

Affected Version(s)

Linux f95eec9bed76d42194c23153cb1cc8f186bf91cb < 35e77467610c4a37cb0ff54ee56b85f73b1f5700

Linux f95eec9bed76d42194c23153cb1cc8f186bf91cb < 0026dbb7de8ea76e97d6edf42fc3cc084564e2bf

Linux f95eec9bed76d42194c23153cb1cc8f186bf91cb

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.