Impact
The Linux kernel’s KVM hypervisor mis‑emulates the INVVPID instruction when a nested guest is active. Instead of invalidating the TLB on the last physical CPU that executed the nested VM, it executes INVVPID on the current host CPU. If the host CPU differs from the nested VM’s previous core, the TLB entries for that core remain stale. An attacker running a nested guest could then read or modify memory that belongs to other virtual machines or the host, thereby breaking the isolation guarantees KVM is intended to provide.
Affected Systems
Linux kernel distributions that support KVM nested virtualization are affected. The vendor name is Linux and the product is the Linux kernel. No specific release or patch level is listed, so any kernel version with KVM and nested virtualization enabled is potentially impacted until the fix commit is applied.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not in the CISA KEV catalog. Successful exploitation requires control of an L1 guest that runs a nested VM; based on the description, it is inferred that an attacker must have sufficient privilege to operate within the virtual machine hierarchy, a scenario attainable by advanced threat actors in compromised environments. If exploited, the attacker could leak or corrupt memory across virtual machines, constituting a serious breach of confidentiality and integrity within a virtualized infrastructure.
OpenCVE Enrichment
Debian DLA
Debian DSA