Database/Kernel, userspace & hypervisor

KVM (nested VMX): Missing CR0/CR4 consistency checks in nVMX - L2 guest can break nested-virt assumptions / crash host
CVSS 6.0CVE-2023-30456Kernel, userspace & hypervisorcurated
Impact
Missing CR0/CR4 consistency checks in nVMX - L2 guest can break nested-virt assumptions / crash host
Who can reach it
Tenant VM guest running nested virtualisation
What to do
Kernel patch + reboot. Cheaper interim control: disable nested virtualisation for tenant VMs, which most GPU tenants do not need
References
Related entries
- Linux kernel (drivers/iommu/intel): On device release VT-d could dereference a NULL domain and, separately, leave theCVE-2024-27079 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (vsock/virtio): Dangling pointer in vskCVE-2024-50264 · Linux kernel (vsock/virtio)Medium
- Linux kernel (drivers/gpu/drm/scheduler): When one tenant's scheduler entity is killed, its scheduled fences are notCVE-2025-38436 · Linux kernel (drivers/gpu/drm/scheduler)Medium
- Linux kernel (drivers/gpu/drm/xe): A batched array of VM_BIND operations could evict other buffer objects belonging toCVE-2025-40086 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel (drivers/gpu/drm/scheduler): Tearing down a GPU scheduler entity takes locks from a fence-signallingCVE-2025-40329 · Linux kernel (drivers/gpu/drm/scheduler)Medium
- Intel CPU (MDS / ZombieLoad): Microarchitectural Fill Buffer Data SamplingCVE-2018-12130 · Intel CPU (MDS / ZombieLoad)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.