Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm/vmx): Between the point where KVM loads the guest's SPEC_CTRL value and the actual VM entry
Impact
Between the point where KVM loads the guest's SPEC_CTRL value and the actual VM entry there were returns that could be resolved from a depleted or guest-influenced RSB, giving speculative execution in host context while host branch protections are already relaxed. The payoff for a tenant is the same as the vmexit case: speculative reads of host kernel memory recovered over a side channel.
Who can reach it
Guest-driven on Intel hosts: the tenant primes predictor state and relies on host NMI activity to drain the RSB in the entry window. High complexity and probabilistic, but requires nothing more than an ordinary vCPU - no host privilege, no passthrough device, no VMM cooperation.
What to do
Patch and reboot into a kernel carrying this fix alongside the vmexit RSB fill (CVE-2022-49611); the two are halves of one mitigation and should be deployed together. No interim runtime control.
References
Related entries
- Linux kernel (arch/x86/kvm/vmx): When a nested VM-Enter fails on invalid guest state, KVM took an open-coded exit pathCVE-2026-68081 · Linux kernel (arch/x86/kvm/vmx)Medium
- Linux kernel (arch/x86/kvm/vmx): KVM's guest/host-mode Intel PT virtualization was broken end to end and theCVE-2024-53135 · Linux kernel (arch/x86/kvm/vmx)High
- Linux kernel (arch/x86/kvm/vmx): Nested teardown freed the shadow VMCS page while vmcs01 still referenced it, andCVE-2026-64562 · Linux kernel (arch/x86/kvm/vmx)High
- Linux kernel (arch/x86/kvm/vmx): The nested vTPR versus TPR-threshold consistency check ran only after KVM had alreadyCVE-2026-72287 · Linux kernel (arch/x86/kvm/vmx)High
- Linux kernel (arch/x86/kvm/vmx): With adaptive PEBS exposed, KVM never guaranteed that LBR MSRs held guest valuesCVE-2024-26992 · Linux kernel (arch/x86/kvm/vmx)High
- Linux kernel (arch/x86/kvm/vmx): The return stack buffer was not refilled on VM exit when the host used IBRS/eIBRS asCVE-2022-49611 · Linux kernel (arch/x86/kvm/vmx)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.