Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm): A nested guest can put an out-of-range virtual-processor ID into an enlightened VMCS and
Impact
A nested guest can put an out-of-range virtual-processor ID into an enlightened VMCS and have KVM index a sparse-bank set with it unchecked, producing an out-of-bounds / use-after-free read in host kernel memory during a paravirtual TLB flush hypercall. A guest gets to read host memory it should never see, and can crash the node.
Who can reach it
Reachable from a guest that has Hyper-V enlightenments and nested virtualization available: the guest runs an L2 vCPU and copies an unbounded VP ID into the enlightened VMCS, then issues an HvFlush hypercall. KASAN caught it from an ordinary unprivileged process running a guest. Conditional on nested virt being exposed to tenants and Hyper-V enlightenments enabled.
What to do
Update to a kernel with the referenced stable commits. Interim: turn off nested virtualization for tenant VMs (kvm_intel nested=0 / kvm_amd nested=0) and disable Hyper-V enlightenments in the guest CPU model until nodes are patched.
References
Related entries
- Linux kernel (arch/x86/kvm): A guest that is not advertised long mode makes the host's SMM emulator walk 16CVE-2022-49883 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A guest that disables paravirtual EOI while KVM still has a pending PV-EOI request, andCVE-2026-72284 · Linux kernel (arch/x86/kvm)High
- Linux kernel (arch/x86/kvm): A failed RSM leaves the vCPU's SMM flag and the MMU role out of sync, so KVM resolves aCVE-2021-47230 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): The guard against accessing bytes 4-15 of an emulated APIC register was dropped, andCVE-2021-47255 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): A guest using its APIC timer in periodic mode can leave KVM programming an already-expiredCVE-2025-71104 · Linux kernel (arch/x86/kvm)Medium
- Linux kernel (arch/x86/kvm): Guest-supplied array indices in the host's local-APIC emulation (an IPI destination id andCVE-2025-39823 · Linux kernel (arch/x86/kvm)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.