Impact
The Linux kernel’s KVM module contains a flaw that suppresses a warning when guest memory is marked dirty after its vCPU has already been destroyed. This suppression prevents the cleanup of writable guest page mappings that are still accessible from userspace, allowing orphan weakness to a gradual exhaustion of system memory or performance degradation on hosts running affected KVM versions.
Affected Systems
All Linux kernel builds incorporating the KVM virtualization subsystem are potentially affected. The issue manifests in scenarios involving SEV‑ES guest VMs when a virtual machine exits without a subsequent KVM_RUN call, resulting while the guest page remains mapped. Any host running a vulnerable kernel and creating SEV‑ES guests may experience this resource leak.
Risk and Exploitability
The EPSS score is reported as < 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of exploitation. Attacks would require privileged access to launch and terminate VMs and do not provide direct code‑execution or escalation paths. The primary risk is a denial‑of‑ to leaked page mappings, which could degrade host performance over time.
OpenCVE Enrichment