← All Advisories

Linux KVM x86 Shadow MMU Checks for an Invalid Root Before Making Shadow Pages Available, Creating Invalid Child Pages When Reclaim Zaps an In-Use Root

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-64561

Key Details

CVECVE-2026-64561
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-08-27
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.

What to Know

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86: Check for invalid/obsolete root *after* making MMU pages available

Check for a "stale" page fault, i.e. for an invalid and/or obsolete root,

after making MMU pages available for the shadow MMU. If reclaiming shadow

pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to

map memory into an invalid root. On its own, populating an invalid root is

"fine", but because child shadow pages inherit their parent's role, any

children created during the map/fetch will be created as invalid pages,

thus violating KVM's invariant that invalid pages are never on the list of

active MMU pages.

Note, the underlying flaw has existed since KVM first started tracking

invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root

pagetables"), but the true badness only came along in 2020 (Linux 5.9)

with the invariant that invalid shadow pages can't be on the list of

active pages.

Note #2, inheriting role.invalid when creating child shadow pages is also

far from ideal; that flaw will be addressed separately. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-64561
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-64561