KVM Vulnerability in Linux Kernel Affecting Virtualization Environment
CVE-2026-64562
What is CVE-2026-64562?
A vulnerability exists within the KVM (Kernel-based Virtual Machine) implementation of the Linux kernel related to the management of shadow VMCS (Virtual Machine Control Structure). When the free_nested() function attempts to free the shadow VMCS while the vmcs01 pointer remains active, it can lead to conditions where the view of the virtual machine state becomes inconsistent. This flaw potentially allows asynchronous execution of VMCLEAR, which can be executed on an incorrect VMCS state if the virtual CPU (vCPU) migrates before the cleanup process completes. The VMCS must remain linked until the VMCLEAR operation is explicitly finalized, ensuring safe memory management and stability in the virtualization environment.
Affected Version(s)
Linux 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5
Linux 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 < 589419470030a89f16cf19300658b6dc644ca946
Linux 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 < 8001d2ce9d9bd09118ce523aef595aa094573ae3