Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm/vmx): With adaptive PEBS exposed, KVM never guaranteed that LBR MSRs held guest values
Impact
With adaptive PEBS exposed, KVM never guaranteed that LBR MSRs held guest values before VM entry, so a guest can request LBR entries in its PEBS records and read back host RIPs - host kernel addresses and host execution paths - straight into the VM. Adaptive records also carry memory-access info that can sidestep the host's PMU event filter, and KVM generated adaptive records even when the guest asked for basic ones.
Who can reach it
Guest-driven and unprivileged inside the VM: the tenant programs PEBS and LBR MSRs from its own vCPU. Requires an Intel host with vPMU enabled and PEBS enumerated in the guest's CPUID - the case whenever performance counters are handed to tenants.
What to do
Update to a stable kernel with the fix (adaptive PEBS support is dropped; no fixed release is enumerated, take the branch with commit 7a7650b3ac23). Interim control: do not expose the vPMU to tenant guests - run with kvm.enable_pmu=0 or strip PEBS/LBR from guest CPUID.
References
Related entries
- Linux kernel (arch/x86/kvm/vmx): The return stack buffer was not refilled on VM exit when the host used IBRS/eIBRS asCVE-2022-49611 · Linux kernel (arch/x86/kvm/vmx)Medium
- Linux kernel (arch/x86/kvm/vmx): Between the point where KVM loads the guest's SPEC_CTRL value and the actual VM entryCVE-2022-49610 · Linux kernel (arch/x86/kvm/vmx)Medium
- Linux kernel (arch/x86/kvm/vmx): When a nested VM-Enter fails on invalid guest state, KVM took an open-coded exit pathCVE-2026-68081 · Linux kernel (arch/x86/kvm/vmx)Medium
- Linux kernel (arch/x86/kvm/vmx): KVM's guest/host-mode Intel PT virtualization was broken end to end and theCVE-2024-53135 · Linux kernel (arch/x86/kvm/vmx)High
- Linux kernel (arch/x86/kvm/vmx): Nested teardown freed the shadow VMCS page while vmcs01 still referenced it, andCVE-2026-64562 · Linux kernel (arch/x86/kvm/vmx)High
- Linux kernel (arch/x86/kvm/vmx): The nested vTPR versus TPR-threshold consistency check ran only after KVM had alreadyCVE-2026-72287 · Linux kernel (arch/x86/kvm/vmx)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.