Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm): An emulated MMIO write that straddles a page boundary onto a second MMIO page is split
Impact
An emulated MMIO write that straddles a page boundary onto a second MMIO page is split into two userspace exits, with the second exit still pointing at an on-stack variable from the first. If the second KVM_RUN comes from a different task, the host kernel reads a freed kernel stack - KASAN caught exactly that. Freed host kernel stack contents flow into data the VM side can observe.
Who can reach it
Started by the guest: it issues a store that splits a page and lands on emulated MMIO on both halves. The freed-stack condition needs the completing KVM_RUN to be issued from a different task, which the VMM process controls - so full weaponisation wants /dev/kvm access (nested-virt tenant or local user), while the guest alone controls the trigger.
What to do
Update to a kernel with the referenced stable commits. Interim: keep /dev/kvm out of tenant containers and disable nested virtualization for tenants on unpatched nodes.
References
Related entries
- Linux kernel (arch/x86/kvm): When KVM failed to program the interrupt remapping table for irq bypass, it left aCVE-2026-72283 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A nested guest can put an out-of-range virtual-processor ID into an enlightened VMCS andCVE-2026-64247 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A guest that is not advertised long mode makes the host's SMM emulator walk 16CVE-2022-49883 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A guest that disables paravirtual EOI while KVM still has a pending PV-EOI request, andCVE-2026-72284 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A failed RSM leaves the vCPU's SMM flag and the MMU role out of sync, so KVM resolves aCVE-2021-47230 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): The guard against accessing bytes 4-15 of an emulated APIC register was dropped, andCVE-2021-47255 · Linux kernel (arch/x86/kvm)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.