VMX Vulnerability in Linux Kernel Affecting QEMU
CVE-2026-64604

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-64604?

A vulnerability exists in the Linux kernel relating to VMX operations during CR8 interception updates. Specifically, the flaw occurs when vmcs12 is grabbed during the CR8 intercept update only if the virtual CPU (vCPU) operates in guest mode. This condition aims to facilitate updates during vCPU creation without breaching the lock dependency assertions of the get_vmcs12() function, which ensures a stable virtual machine state. Debugging alerts have been triggered, indicating potential issues when these conditions are not met. While the vulnerability does not introduce functional changes, it highlights an important aspect of virtual machine management that needs to be monitored for optimal security.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9a21f1defd96c6301c5fb462a78eb51b191bd2dd

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 570af5db081b87374594a00711ac5760d2ea6844

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.