Database/Kernel, userspace & hypervisor

Linux kernel (virt/kvm): The dirty-ring reset path bounds-checks an offset with unchecked 64-bit arithmetic, so a
Impact
The dirty-ring reset path bounds-checks an offset with unchecked 64-bit arithmetic, so a crafted pair of ring entries wraps the sum past the check. KVM then indexes the memslot's rmap array with a near-U64_MAX GFN - an out-of-bounds load followed by a conditional bit clear through whatever pointer that load produced. That is an attacker-influenced write into host kernel memory and a straight path to root on the node.
Who can reach it
The commit states it plainly: reachable from any process holding /dev/kvm. The dirty ring is mapped MAP_SHARED into the process, so it rewrites the slot/offset payload of queued entries and then calls KVM_RESET_DIRTY_RINGS. Needs the legacy/shadow MMU path (shadow paging, any VM that allocated shadow roots, or a write-tracked slot). Relevant wherever tenants can open /dev/kvm - nested-virt-enabled VMs, or bare-metal tenants with KVM exposed.
What to do
Update to a kernel carrying the referenced stable commits. Interim: do not expose /dev/kvm to tenant containers, and disable nested virtualization for tenant VMs so guests cannot run their own KVM.
References
Related entries
- Linux kernel (virt/kvm): Unbinding a memslot from a guest_memfd was skipped once the file was already dying, so if theCVE-2025-40274 · Linux kernel (virt/kvm)High
- Linux kernel (virt/kvm): KVM blocked turning KVM_MEM_GUEST_MEMFD on for an existing memslot but not turning it off, andCVE-2025-68810 · Linux kernel (virt/kvm)High
- Linux kernel (virt/kvm): A guest store that splits a page and lands on a datamatch-enabled ioeventfd reaches a BUG_ONCVE-2026-63806 · Linux kernel (virt/kvm)High
- Linux kernel (arch/x86/kvm/svm): VMLOAD/VMSAVE executed by an L2 guest and not intercepted by L1 were emulated againstCVE-2026-43133 · Linux kernel (arch/x86/kvm/svm)High
- util-linux nsenter: --join-cgroup leaks a root-opened cgroup.procs fd into the target containerCVE-2026-78408 · util-linux nsenter (--join-cgroup descriptor leak across execve)High
- Linux kernel KVM/arm64: guest-controlled TLBI Range can overflow the hypervisor's range computationCVE-2026-89911 · Linux kernel KVM arm64 (TLBI by Range)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.