GPU VulnDB

Database/Kernel, userspace & hypervisor

KVM PPC Book3S HV: use-after-free on nested guest struct during all-LPID tlbie emulation

UnscoredCVE-2026-98283Kernel, userspace & hypervisorcurated

Impact

kvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops mmu_lock without taking a reference on the kvm_nested_guest pointer. A concurrent vCPU issuing a single-LPID tlbie can race the guest through kvmhv_remove_nested() to kfree(gp), leaving the iterating vCPU with a dangling pointer that it then locks and dereferences. The commit message states the free path is fully L1-controlled, so a nested-virtualization guest can drive the race from inside the VM against host kernel memory - the strongest class of guest-to-host escape primitive. Confined to POWER Book3S HV hosts running nested guests.

Who can reach it

An L1 guest on a powerpc KVM HV host, running nested virtualization, issuing tlbie instructions. Requires only guest-level code execution - no host authentication.

What to do

Apply the stable fix that takes gp->refcnt before dropping mmu_lock and releases it with kvmhv_put_nested(). Kernel update and host reboot: evacuate or shut down guests on the node. Where nested virtualization is not needed on POWER hosts, disabling it removes the exposure. No CVSS score or vendor advisory in the record.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.