In the Linux kernel, the following vulnerability has been resolved:
KVM: nVMX: Hide shadow VMCS right after VMCLEAR
free_nested() frees the shadow VMCS while vmcs01 still points to it. But
because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU
might migrate before the pointer is cleared and __loaded_vmcs_clear()
may then execute VMCLEAR.
The VMCS needs to stay attached until its explicit VMCLEAR completes, but
then it can be hidden and the page safely freed.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-04 07:16
Updated : 2026-08-19 17:20
NVD link : CVE-2026-64562
Mitre link : CVE-2026-64562
CVE.ORG link : CVE-2026-64562
JSON object : View
Products Affected
No product.
CWE
No CWE.
