KVM: x86: Check for invalid/obsolete root *after* making MMU pages available

Summary

CVECVE-2026-64561
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-04 07:16:30 UTC
Updated2026-08-04 07:16:30 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected f95eec9bed76d42194c23153cb1cc8f186bf91cb 35e77467610c4a37cb0ff54ee56b85f73b1f5700 git Not specified
CNA Linux Linux affected f95eec9bed76d42194c23153cb1cc8f186bf91cb 0026dbb7de8ea76e97d6edf42fc3cc084564e2bf git Not specified
CNA Linux Linux affected f95eec9bed76d42194c23153cb1cc8f186bf91cb f3477a6a4164f15287444eda685b5f6405dbd1e5 git Not specified
CNA Linux Linux affected f95eec9bed76d42194c23153cb1cc8f186bf91cb bce0d3c26e2c761a4bf43c8949f333fc7374eb2d git Not specified
CNA Linux Linux affected f95eec9bed76d42194c23153cb1cc8f186bf91cb 2abd5287f08319fa35764566b15c6e22cb1068db git Not specified
CNA Linux Linux affected 5.9 Not specified
CNA Linux Linux unaffected 5.9 semver Not specified
CNA Linux Linux unaffected 6.6.148 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.101 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.42 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.6 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc5 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/0026dbb7de8ea76e97d6edf42fc3cc084564e2bf 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/bce0d3c26e2c761a4bf43c8949f333fc7374eb2d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/35e77467610c4a37cb0ff54ee56b85f73b1f5700 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2abd5287f08319fa35764566b15c6e22cb1068db 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f3477a6a4164f15287444eda685b5f6405dbd1e5 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report