Memory Access Vulnerability in Linux Kernel on KVM-enabled Hosts
CVE-2026-80853

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80853?

In the Linux kernel, a vulnerability has been identified that affects KVM (Kernel-based Virtual Machine) on SEV (Secure Encrypted Virtualization) and SEV-ES (Secure Encrypted Virtualization-Encrypted State) guests hosted on SNP (Secure Nested Paging)-compatible platforms. This vulnerability stems from the failure to allocate full 4KiB pages for temporary buffers used in memory encryption and decryption operations. When transferring page ownership to firmware, the resulting inaccessibility to software can trigger unexpected memory access violations. This could lead to kernel panics and other operational disruptions due to concurrent memory allocations by other kernel processes. The resolution entails ensuring that proper page allocation practices are followed during cryptographic operations to maintain system integrity and stability.

Affected Version(s)

Linux 4c735bf1bc22fd6ee66ab4bffe1d7599c3964781 < 97f6402f5950ca3450541287c4b3664f3acda976

Linux 4c735bf1bc22fd6ee66ab4bffe1d7599c3964781

Linux 7.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.