Database/Kernel, userspace & hypervisor

Linux kernel (virt/kvm): KVM blocked turning KVM_MEM_GUEST_MEMFD on for an existing memslot but not turning it off, and
Impact
KVM blocked turning KVM_MEM_GUEST_MEMFD on for an existing memslot but not turning it off, and clearing the flag left the guest_memfd binding in place. Releasing the file then writes through a stale pointer - a KASAN-confirmed slab use-after-free in host kernel memory, i.e. a kernel memory-corruption primitive for whoever can drive VM lifecycle ioctls.
Who can reach it
Not reachable from inside a guest. It is reached from the process holding the VM file descriptor via KVM_SET_USER_MEMORY_REGION2 with the guest_memfd flag cleared. The VMM is trusted here, so this matters on nodes where untrusted local users or tenant-run VMM processes can open /dev/kvm - there it is a local privilege-escalation primitive. guest_memfd is the backing store for confidential VMs (SEV-SNP / TDX), so confidential-compute nodes are the ones carrying this code.
What to do
Update to a stable kernel with the linked fix (no fixed release is enumerated; take the branch carrying commit 9935df5333aa). Interim control: keep /dev/kvm off tenant containers and restrict it to the operator's VMM service account; do not let tenants run their own VMM process on shared nodes.
References
Related entries
- Linux kernel (virt/kvm): A guest store that splits a page and lands on a datamatch-enabled ioeventfd reaches a BUG_ONCVE-2026-63806 · Linux kernel (virt/kvm)High
- Linux kernel (virt/kvm): The dirty-ring reset path bounds-checks an offset with unchecked 64-bit arithmetic, so aCVE-2026-52969 · Linux kernel (virt/kvm)High
- Linux kernel (virt/kvm): Unbinding a memslot from a guest_memfd was skipped once the file was already dying, so if theCVE-2025-40274 · Linux kernel (virt/kvm)High
- Linux kernel (drivers/iommu): In an SVA context the IOMMU walks and caches the CPU's page tables, and on x86 everyCVE-2025-71089 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/gpu/drm/xe): The observation-config ioctl dereferences the config object after releasing the lockCVE-2025-71099 · Linux kernel (drivers/gpu/drm/xe)High
- libvirt: integer overflow in NodeGetFreePages gives a local user heap corruption in the root daemonCVE-2026-18917 · libvirt (NodeGetFreePages RPC handler)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.