Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm/vmx): Nested teardown freed the shadow VMCS page while vmcs01 still referenced it, and
Impact
Nested teardown freed the shadow VMCS page while vmcs01 still referenced it, and because the clear is asynchronous a vCPU that migrates afterwards makes the CPU execute VMCLEAR against a page already returned to the allocator. That is hardware writing into reallocated host kernel memory - a use-after-free in the host driven by ordinary nested-VMX activity in a guest.
Who can reach it
Guest-driven: a tenant uses VMX inside its VM and then tears the nested state down (VMCLEAR/VMXOFF, or nested state teardown), and the freed page is written when the vCPU is next scheduled on a different physical CPU. Requires nested VMX exposed to the guest (Intel host, kvm_intel nested=1, VMX in guest CPUID). No host privilege needed.
What to do
Update to a stable kernel with the linked fix (no fixed release enumerated; take the branch carrying commit dc3eecfa219e). Interim control: disable nested virtualization for tenant guests (kvm_intel.nested=0) - that removes the whole path.
References
Related entries
- Linux kernel (arch/x86/kvm/vmx): The nested vTPR versus TPR-threshold consistency check ran only after KVM had alreadyCVE-2026-72287 · Linux kernel (arch/x86/kvm/vmx)High
- Linux kernel (arch/x86/kvm/vmx): With adaptive PEBS exposed, KVM never guaranteed that LBR MSRs held guest valuesCVE-2024-26992 · Linux kernel (arch/x86/kvm/vmx)High
- Linux kernel (arch/x86/kvm/vmx): The return stack buffer was not refilled on VM exit when the host used IBRS/eIBRS asCVE-2022-49611 · Linux kernel (arch/x86/kvm/vmx)Medium
- Linux kernel (arch/x86/kvm/vmx): Between the point where KVM loads the guest's SPEC_CTRL value and the actual VM entryCVE-2022-49610 · Linux kernel (arch/x86/kvm/vmx)Medium
- Linux kernel (arch/x86/kvm/vmx): When a nested VM-Enter fails on invalid guest state, KVM took an open-coded exit pathCVE-2026-68081 · Linux kernel (arch/x86/kvm/vmx)Medium
- Linux kernel (arch/x86/kvm/vmx): KVM's guest/host-mode Intel PT virtualization was broken end to end and theCVE-2024-53135 · Linux kernel (arch/x86/kvm/vmx)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.