Database/Kernel, userspace & hypervisor

Linux kernel (virt/kvm): Unbinding a memslot from a guest_memfd was skipped once the file was already dying, so if the
Impact
Unbinding a memslot from a guest_memfd was skipped once the file was already dying, so if the memslot is freed first the release path writes eight bytes through a freed pointer. syzbot and KASAN confirm the slab use-after-free write in host kernel memory - a straightforward kernel corruption primitive on nodes that run confidential VMs.
Who can reach it
Reached through KVM ioctls on the VM fd (memslot deletion racing guest_memfd close), not from inside a guest. Under a trusted-VMM model this is not a tenant path; it becomes one wherever untrusted local users or tenant-controlled VMM processes hold /dev/kvm, where it is a local privilege-escalation primitive. Only nodes with guest_memfd in use (SEV-SNP / TDX confidential VMs) exercise this code.
What to do
Update to a stable kernel carrying the linked fix (no fixed release enumerated; take the branch containing commit ae431059e75d). Interim control: keep /dev/kvm out of tenant containers and restricted to the operator's VMM account.
References
Related entries
- Linux kernel (virt/kvm): KVM blocked turning KVM_MEM_GUEST_MEMFD on for an existing memslot but not turning it off, andCVE-2025-68810 · Linux kernel (virt/kvm)High
- Linux kernel (virt/kvm): A guest store that splits a page and lands on a datamatch-enabled ioeventfd reaches a BUG_ONCVE-2026-63806 · Linux kernel (virt/kvm)High
- Linux kernel (virt/kvm): The dirty-ring reset path bounds-checks an offset with unchecked 64-bit arithmetic, so aCVE-2026-52969 · Linux kernel (virt/kvm)High
- Linux kernel (drivers/gpu/drm/vmwgfx): The vmwgfx command-buffer parser trusted a size field taken straight from theCVE-2025-40277 · Linux kernel (drivers/gpu/drm/vmwgfx)High
- VMware Aria Operations / VMware Tools: Local privilege escalation to root inside a managed VM via SDMP service discoveryCVE-2025-41244 · VMware Aria Operations / VMware ToolsHigh
- PAM (pam-config): Local user is treated as `allow_active` in PAMCVE-2025-6018 · PAM (pam-config)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.