Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm/svm): If AVIC is inhibited while a nested guest is running, KVM leaves the x2APIC MSRs
Impact
If AVIC is inhibited while a nested guest is running, KVM leaves the x2APIC MSRs unintercepted for the outer guest. That guest can then read most of the host's real APIC state, send arbitrary interrupts to host CPUs (including the posted-interrupt wakeup vector), change host task priority, and trivially take the node down. This is a guest reaching directly into host interrupt state.
Who can reach it
Driven from inside a guest on an AMD host: the guest starts a nested VM while AVIC is fully enabled, then triggers a VM-scoped AVIC inhibit, and afterwards issues raw x2APIC MSR reads/writes from L1. Requires AMD hardware with AVIC enabled and nested virtualization exposed to the tenant. Not reachable from a plain container tenant.
What to do
Update to a kernel with the referenced stable commits. Interim: disable AVIC on affected AMD nodes (kvm_amd avic=0) and/or stop exposing nested virtualization to tenants (kvm_amd nested=0) until patched.
References
Related entries
- Linux kernel (arch/x86/kvm/svm): VMLOAD/VMSAVE executed by an L2 guest and not intercepted by L1 were emulated againstCVE-2026-43133 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): The SEV debug-encrypt path bounds each iteration by the source page offset but not theCVE-2026-63794 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): After a CPU offline/online cycle, KVM's ASID generation counter is reset in a way thatCVE-2026-68093 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): On AMD hosts that cannot report the next RIP, KVM's WRMSR/HLT/INVD fastpath has toCVE-2025-40038 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): Page State Change requests from a confidential guest were validated against theCVE-2026-63938 · Linux kernel (arch/x86/kvm/svm)Critical
- Linux kernel (arch/x86/kvm/svm): KVM computed the usable size of the guest-provided GHCB scratch area wrongly, so aCVE-2026-63939 · Linux kernel (arch/x86/kvm/svm)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.