Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm/mmu): If reclaiming shadow pages invalidates the root a fault is being serviced against, KVM
Impact
If reclaiming shadow pages invalidates the root a fault is being serviced against, KVM maps into that invalid root and creates child shadow pages that inherit the invalid role, putting invalid pages on the active MMU list. That breaks the invariant the zapping code relies on, leaving live shadow-page-table state pointing at pages KVM believes are gone - the classic setup for a host-side use-after-free reachable from guest page faults.
Who can reach it
Reachable from an ordinary guest: fault in enough memory to push the shadow MMU into reclaiming pages while a root is being used, on any node where the shadow MMU is active (nested guests, or guests running without TDP). No host access required.
What to do
Update to a kernel with the referenced stable commits. Interim: keep TDP MMU enabled and avoid exposing nested virtualization to tenants on unpatched nodes; consider raising kvm.mmu_shadow_page limits so reclaim is not hit under normal tenant load.
References
Related entries
- Linux kernel (arch/x86/kvm/mmu): The TDP MMU skipped invalid roots when unmapping a GFN range, so KVM could still holdCVE-2021-47639 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (arch/x86/kvm/mmu): When guest memory is backed by a VM_PFNMAP mapping, KVM derived the target page frameCVE-2022-49562 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (arch/x86/kvm/mmu): The shadow MMU derives GFNs for direct shadow pages arithmetically, which breaks ifCVE-2026-46113 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (arch/x86/kvm/mmu): Shadow-page lookup reuses a page without comparing its role, so a direct (2MB) shadowCVE-2026-53359 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (arch/x86/kvm/mmu): A guest that creates a hugepage mapping extending below the bounds of a memslot makesCVE-2026-63807 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (arch/x86/kvm/vmx): Nested teardown freed the shadow VMCS page while vmcs01 still referenced it, andCVE-2026-64562 · Linux kernel (arch/x86/kvm/vmx)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.