KernelScan.io

HIGH Introduced in 4.20

kvm NestedGuest UAF

CVE-2026-98283

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

KernelScan AI7.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid() kvmhv_emulate_tlbie_all_lpid() iterates the nested-guest IDR and drops mmu_lock before calling kvmhv_emulate_tlbie_lpid(), but does not hold a reference on the kvm_nested_guest pointer obtained from the IDR. A concurrent vCPU issuing a single-LPID tlbie (is=2, ric=2) can race through kvmhv_flush_nested() -> kvmhv_remove_nested() -> idr_remove / --refcnt -> kvmhv_release_nested() -> kfree(gp) in that window, leaving the iterating vCPU with a dangling pointer. The subsequent mutex_lock(&gp->tlb_lock) and accesses to gp->shadow_pgtable, gp->shadow_lpid and gp->l1_host all touch freed memory. The free path is fully L1-controlled. Fix this by incrementing gp->refcnt inside the loop before dropping mmu_lock, mirroring what kvmhv_get_nested() does, and releasing the reference with kvmhv_put_nested() after the per-guest work completes. This is the same get/put discipline already used at every other call site that drops mmu_lock while holding a nested-guest pointer.

02

Engine v0.7.0

Risk summary

An L1 guest VM running on a PowerPC KVM hypervisor with nested virtualization can trigger a use-after-free in the host kernel by racing two concurrent TLB invalidation hcalls. This can lead to kernel memory corruption, potentially allowing the guest to escape to the host. The vulnerability requires PowerPC hardware with KVM Book3S HV nested virtualization enabled.

Affectedarch/powerpc/kvm/book3s_hv_nested.c (KVM PPC Book3S HV nested virtualization)

Vulnerability analysis

When an L1 guest on a PowerPC KVM hypervisor issues a TLB invalidation covering all nested guests, the host's KVM code iterates over nested-guest structures and releases its lock before performing per-guest cleanup, but without taking a reference count on each structure. A concurrent L1 vCPU issuing a single-guest TLB invalidation can race through the removal path and free the nested-guest structure during that window, leaving the iterating vCPU with a dangling pointer whose subsequent lock and field accesses touch freed memory. The fix increments the reference count before dropping the lock and releases it after the per-guest work completes, matching the discipline already used at every other call site that drops the lock while holding a nested-guest pointer. This is reachable from an unprivileged L1 guest VM on PowerPC hardware with KVM Book3S HV nested virtualization enabled; no host-level privileges are required.

03

BranchIntroducedFixed inPatch commit
6.14.206.1.1894d8f7b1f5863
6.64.206.6.158e37fba1ba693
6.124.206.12.11224b634852413
6.184.206.18.54fbf69b7d0555
7.24.207.2.8ec2d7a52b399
mainline4.207.3-rc451938dfa8a51