KVM Vulnerability in Linux Kernel Affecting Virtualization Environment
CVE-2026-64562

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-64562?

A vulnerability exists within the KVM (Kernel-based Virtual Machine) implementation of the Linux kernel related to the management of shadow VMCS (Virtual Machine Control Structure). When the free_nested() function attempts to free the shadow VMCS while the vmcs01 pointer remains active, it can lead to conditions where the view of the virtual machine state becomes inconsistent. This flaw potentially allows asynchronous execution of VMCLEAR, which can be executed on an incorrect VMCS state if the virtual CPU (vCPU) migrates before the cleanup process completes. The VMCS must remain linked until the VMCLEAR operation is explicitly finalized, ensuring safe memory management and stability in the virtualization environment.

Affected Version(s)

Linux 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5

Linux 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 < 589419470030a89f16cf19300658b6dc644ca946

Linux 355f4fb1405ec29d0fac49b4d41fcd78cbd455d5 < 8001d2ce9d9bd09118ce523aef595aa094573ae3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.