KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation

Summary

CVECVE-2026-43133
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-05-06 12:16:30 UTC
Updated2026-07-15 02:21:42 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state") made KVM always use vmcb01 for the fields controlled by VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code to always use vmcb01. As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01 instead of the current VMCB.

Risk And Classification

Primary CVSS: v3.1 7.9 HIGH from ADP

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

EPSS: 0.000130000 probability, percentile 0.022800000 (date 2026-05-12)

Problem Types: NVD-CWE-noinfo | CWE-628 | CWE-628 Function Call with Incorrectly Specified Arguments


VersionSourceTypeScoreSeverityVector
3.1ADPCVSS7.9HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary7.9HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
3.10b0ca135-0b70-47e7-9f44-1890c2a1c46cSecondary7.9HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
3.1CNADECLARED7.9HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected cc3ed80ae69f454c3d904af9f65394a540099723 10063e1251c1485034a018236080792ad083dcc5 git Not specified
CNA Linux Linux affected cc3ed80ae69f454c3d904af9f65394a540099723 c3b7015000988ba35ecd5648f4b2283960f00543 git Not specified
CNA Linux Linux affected cc3ed80ae69f454c3d904af9f65394a540099723 3880e331b0b31d0d5d3702b124f6c93539cd478a git Not specified
CNA Linux Linux affected cc3ed80ae69f454c3d904af9f65394a540099723 fce2fd4a2ca05670a91015aacccf96a1c26268fd git Not specified
CNA Linux Linux affected cc3ed80ae69f454c3d904af9f65394a540099723 d464cf1ed900d47c85393d40b00017b6adfc2e6c git Not specified
CNA Linux Linux affected cc3ed80ae69f454c3d904af9f65394a540099723 0004ecb798b30e90d7ebfe74efae2d9423315a64 git Not specified
CNA Linux Linux affected cc3ed80ae69f454c3d904af9f65394a540099723 127ccae2c185f62e6ecb4bf24f9cb307e9b9c619 git Not specified
CNA Linux Linux affected 5.13 Not specified
CNA Linux Linux unaffected 5.13 semver Not specified
CNA Linux Linux unaffected 5.15.202 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.165 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.128 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.75 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.16 6.18.* semver Not specified
CNA Linux Linux unaffected 6.19.6 6.19.* semver Not specified
CNA Linux Linux unaffected 7.0 * original_commit_for_fix Not specified
ADP Red Hat Red Hat Enterprise Linux 10 Not specified Not specified
ADP Red Hat Red Hat Enterprise Linux 10 Not specified Not specified
ADP Red Hat Red Hat Enterprise Linux 6 Not specified Not specified
ADP Red Hat Red Hat Enterprise Linux 7 Not specified Not specified
ADP Red Hat Red Hat Enterprise Linux 7 Not specified Not specified
ADP Red Hat Red Hat Enterprise Linux 8 Not specified Not specified
ADP Red Hat Red Hat Enterprise Linux 8 Not specified Not specified
ADP Red Hat Red Hat Enterprise Linux 9 Not specified Not specified
ADP Red Hat Red Hat Enterprise Linux 9 Not specified Not specified
ADP Red Hat Red Hat OpenShift Container Platform 4 Not specified Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/127ccae2c185f62e6ecb4bf24f9cb307e9b9c619 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43133.json 0b0ca135-0b70-47e7-9f44-1890c2a1c46c security.access.redhat.com
git.kernel.org/stable/c/10063e1251c1485034a018236080792ad083dcc5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/0004ecb798b30e90d7ebfe74efae2d9423315a64 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/d464cf1ed900d47c85393d40b00017b6adfc2e6c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
access.redhat.com/security/cve/CVE-2026-43133 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
bugzilla.redhat.com/show_bug.cgi 0b0ca135-0b70-47e7-9f44-1890c2a1c46c bugzilla.redhat.com
git.kernel.org/stable/c/c3b7015000988ba35ecd5648f4b2283960f00543 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/fce2fd4a2ca05670a91015aacccf96a1c26268fd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/3880e331b0b31d0d5d3702b124f6c93539cd478a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Additional Advisory Data

SourceTimeEvent
ADP2026-05-06T00:00:00.000ZReported to Red Hat.
ADP2026-05-06T00:00:00.000ZMade public.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report