Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm/svm): Hardware ignores the low five bits of CR3 when loading PDPTEs, but KVM's nested SVM
Impact
Hardware ignores the low five bits of CR3 when loading PDPTEs, but KVM's nested SVM path did not, so an L1 guest can offset where the host reads the page-directory-pointer table from. Upstream states the worst case is an out-of-bounds read - if the target page sits at the end of a memslot and the VMM is not using guard pages, the host reads past it and feeds the result into the nested page-table walker.
Who can reach it
Guest-driven: a tenant with nested virtualization exposed sets nCR3 with bits 4:0 non-zero and executes VMRUN with PAE paging in L2. Requires an AMD host with kvm_amd nested=1 and SVM advertised in the guest's CPUID; not reachable if nested virt is withheld from tenants.
What to do
Update to a stable kernel with the linked fix (no fixed release enumerated; take the branch carrying commit 6876793907cb). Interim control: disable nested virtualization for tenant guests (kvm_amd.nested=0, drop SVM from guest CPUID).
References
Related entries
- Linux kernel (arch/x86/kvm/svm): If AVIC is inhibited while a nested guest is running, KVM leaves the x2APIC MSRsCVE-2026-74516 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): VMLOAD/VMSAVE executed by an L2 guest and not intercepted by L1 were emulated againstCVE-2026-43133 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): The SEV debug-encrypt path bounds each iteration by the source page offset but not theCVE-2026-63794 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): After a CPU offline/online cycle, KVM's ASID generation counter is reset in a way thatCVE-2026-68093 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): On AMD hosts that cannot report the next RIP, KVM's WRMSR/HLT/INVD fastpath has toCVE-2025-40038 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): Page State Change requests from a confidential guest were validated against theCVE-2026-63938 · Linux kernel (arch/x86/kvm/svm)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.