CRITICAL Introduced in 6.8
kvm NestedStatePages Corruption
CVE-2026-89931
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit Always check and clear KVM_REQ_GET_NESTED_STATE_PAGES when emulating a nested VM-Exit to ensure the request is cleared, even when KVM was built with CONFIG_KVM_HYPERV=n, as KVM subtly relies on the "check" to clear the flag and thus avoid double-mapping the vmcs12 pages, e.g. if KVM manages to bail from VM-Enter without processing the request, and then emulates VMLAUNCH or VMRESUME.
02KernelScan AI Analysis
Risk summary
A malicious guest VM running on a KVM host with nested virtualization enabled and Hyper-V emulation compiled out can trigger double-mapping of nested state pages, leading to host kernel memory corruption. This is a VM-to-host escape primitive that could result in information disclosure, integrity violation, or denial of service on the host. Hosts not using nested virtualization or with CONFIG_KVM_HYPERV enabled are not affected.
Vulnerability analysis
When the hypervisor is built without Hyper-V emulation support, a request to prepare nested state pages is never cleared when a nested virtual machine exits, because the clearing code was conditionally compiled out. If the hypervisor aborts entering a nested virtual machine without processing this request, then later resumes or launches another nested virtual machine, the state pages can be mapped twice, corrupting host kernel memory. The fix ensures the request is always checked and cleared on nested exit regardless of configuration, while keeping the Hyper-V-specific handling conditional. A malicious guest virtual machine running on a host with nested virtualization enabled can trigger this when Hyper-V emulation is disabled.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 6.8 | 6.12.110 | ae190f2439ca |
| 6.18 | 6.8 | 6.18.51 | 674a3244f07f |
| 7.2 | 6.8 | 7.2.5 | bbec4adc2f34 |
| mainline | 6.8 | 7.3-rc1 | 11722439fb20 |