Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm/mmu): When guest memory is backed by a VM_PFNMAP mapping, KVM derived the target page frame
Impact
When guest memory is backed by a VM_PFNMAP mapping, KVM derived the target page frame from vm_pgoff, which is a file offset and has nothing to do with the mapped pfn. Updating guest page-table accessed/dirty bits therefore wrote into effectively arbitrary host physical pages - a tenant's ordinary page-table walks corrupt host memory outside its own VM.
Who can reach it
Guest-driven with no special guest privilege: every vCPU memory access can cause KVM to set A/D bits during a shadow page-table walk. Reachable whenever any part of the guest's address space is backed by a VM_PFNMAP VMA - device memory, /dev/mem backing, or a passthrough BAR mapped into the guest, which is the normal shape of a GPU-passthrough VM.
What to do
Update to a stable kernel containing the linked fix (no fixed release is enumerated in the record; take the branch carrying commit f122dfe44768). Interim control: back tenant VMs with ordinary anonymous/hugetlb memory only and avoid VM_PFNMAP-backed memslots, including /dev/mem-backed regions, on unpatched hosts.
References
Related entries
- Linux kernel (arch/x86/kvm/mmu): The shadow MMU derives GFNs for direct shadow pages arithmetically, which breaks ifCVE-2026-46113 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (arch/x86/kvm/mmu): Shadow-page lookup reuses a page without comparing its role, so a direct (2MB) shadowCVE-2026-53359 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (arch/x86/kvm/mmu): A guest that creates a hugepage mapping extending below the bounds of a memslot makesCVE-2026-63807 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (arch/x86/kvm/mmu): If reclaiming shadow pages invalidates the root a fault is being serviced against, KVMCVE-2026-64561 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (arch/x86/kvm/mmu): The TDP MMU skipped invalid roots when unmapping a GFN range, so KVM could still holdCVE-2021-47639 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (drivers/gpu/drm/i915/gt): The GPU migration copy path used plain ints for sizes that a tenant controlsCVE-2022-49963 · Linux kernel (drivers/gpu/drm/i915/gt)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.