Database/Kernel, userspace & hypervisor

KVM PPC Book3S HV: use-after-free on nested guest struct during all-LPID tlbie emulation
Impact
kvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops mmu_lock without taking a reference on the kvm_nested_guest pointer. A concurrent vCPU issuing a single-LPID tlbie can race the guest through kvmhv_remove_nested() to kfree(gp), leaving the iterating vCPU with a dangling pointer that it then locks and dereferences. The commit message states the free path is fully L1-controlled, so a nested-virtualization guest can drive the race from inside the VM against host kernel memory - the strongest class of guest-to-host escape primitive. Confined to POWER Book3S HV hosts running nested guests.
Who can reach it
An L1 guest on a powerpc KVM HV host, running nested virtualization, issuing tlbie instructions. Requires only guest-level code execution - no host authentication.
What to do
Apply the stable fix that takes gp->refcnt before dropping mmu_lock and releases it with kvmhv_put_nested(). Kernel update and host reboot: evacuate or shut down guests on the node. Where nested virtualization is not needed on POWER hosts, disabling it removes the exposure. No CVSS score or vendor advisory in the record.
References
Related entries
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
- Incus: instance snapshots bypass restricted.containers.lowlevel, giving command execution on the hostCVE-2026-48751 · Incus (instance snapshots ignore restricted.containers.lowlevel)Critical
- VMware ESXi (OpenSLP): Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisorCVE-2020-3992 · VMware ESXi (OpenSLP)Critical
- Linux kernel mlx5_core kTLS RX offload: TLS RX resync list corruption: entries are moved by the resync handlerCVE-2021-47215 · Linux kernel mlx5_core kTLS RX offloadCritical
- Linux kernel (drivers/nvme/host): The NVMe/RDMA initiator destroys the queue pair before the connection manager ID, soCVE-2021-47378 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (net/tls): KTLS stored a negative errno into the socket error field where a positive value is expected. ACVE-2021-47496 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.