Impact
The Linux kernel's KVM hypervisor contains a flaw that causes vmcs12 pages to remain pinned when a nested VM-Enter fails due to an invalid guest state. The unpinned pages leak mapped guest memory, enabling an attacker who can influence the guest to read host memory contents that should remain confidential. This vulnerability is a form of information disclosure via improper resource handling.
Affected Systems
The flaw affects any Linux system that runs the Linux kernel with KVM enabled and contains the unpatched nVMX code path. The vendor is the Linux kernel team, and the affected product is the Linux kernel itself. No specific kernel versions are listed, so any kernel that has not applied the corresponding patch is susceptible.
Risk and Exploitability
The CVSS score is not supplied, but the EPSS score is not available and the flaw is not listed in the CISA KEV catalog. An attacker would need a nested virtual machine on a host running KVM, and a capability to force the guest into an invalid state that triggers VM-Enter. While the attack requires privileged nested VM operations, the information that may be disclosed could be highly sensitive, so the risk is high for a properly configured host.
OpenCVE Enrichment