Linux Kernel Vulnerability in KVM: Potential Access to Unavailable Devices
CVE-2026-80921
What is CVE-2026-80921?
The vulnerability in the Linux kernel’s KVM (Kernel-based Virtual Machine) component pertains to improper handling of cryptocurrency access bits from a specific format0 apcb (Access Control Block). When shadowing the access bits associated with crypto operations, bits from 64 to 255 may remain unchanged from the vsie page in the crycb (Crypto Control Block). This oversight can grant a nested guest the ability to access a now-unavailable device, raising significant security concerns. The resolution involves proper zeroing of the affected bits, thereby preventing unauthorized access.
Affected Version(s)
Linux 6b79de4b056e5a2febc0c61233d8f0ad7868e49c
Linux 6b79de4b056e5a2febc0c61233d8f0ad7868e49c < 59d51550b5cb916bda037673a721a404b3b47a0d
Linux 6b79de4b056e5a2febc0c61233d8f0ad7868e49c