Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU

When emulating INVVPID, KVM executes INVVPID on the physical CPU using
vpid02 (instead of the L1 assigned VPID), after doing some validations
on the operands. However, it is possible that the physical CPU KVM
executes INVVPID on is different from the CPU L2 is running on.

For example, in the following scenario:
- L2 runs on CPU #1 and exits to L1 (vmx->nested.vmcs02.cpu=1)
- L1 migrates to CPU #2 and executes INVVPID
- KVM executes INVVPID on CPU #2
- L1 migrates back to CPU #1 and runs L2 (vmx->nested.vmcs02.cpu=1)

The TLB entries on CPU #1 are never invalidated, because INVVPID was
executed on CPU #2, and vmcs02 never ran on a different pCPU (i.e.
vmx_vcpu_load_vmcs() will *not* request KVM_REQ_TLB_FLUSH).

Ensure that INVVPID is being executed on the same pCPU that L2 last ran
on, and if not, fallback to clearing last_vpid=0 to trigger a full VPID
flush on the next nested VM-Enter (as KVM will detect L1 using a
different VPID for L2). If L2 ends up running on a different pCPU, KVM
will flush the TLB anyway through vmx_vcpu_load_vmcs().
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory isolation breach via stale TLB entries
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s KVM hypervisor mis‑emulates the INVVPID instruction when a nested guest is active. Instead of invalidating the TLB on the last physical CPU that executed the nested VM, it executes INVVPID on the current host CPU. If the host CPU differs from the nested VM’s previous core, the TLB entries for that core remain stale. An attacker running a nested guest could then read or modify memory that belongs to other virtual machines or the host, thereby breaking the isolation guarantees KVM is intended to provide.

Affected Systems

Linux kernel distributions that support KVM nested virtualization are affected. The vendor name is Linux and the product is the Linux kernel. No specific release or patch level is listed, so any kernel version with KVM and nested virtualization enabled is potentially impacted until the fix commit is applied.

Risk and Exploitability

The CVSS score of 8.8 classifies the flaw as high severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not in the CISA KEV catalog. Successful exploitation requires control of an L1 guest that runs a nested VM; based on the description, it is inferred that an attacker must have sufficient privilege to operate within the virtual machine hierarchy, a scenario attainable by advanced threat actors in compromised environments. If exploited, the attacker could leak or corrupt memory across virtual machines, constituting a serious breach of confidentiality and integrity within a virtualized infrastructure.

Generated by OpenCVE AI on September 18, 2026 at 08:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel release that contains the commit fixing the INVVPID emulation bug – the patch referenced in the advisory removes the incorrect CPU selection logic.
  • If an upgrade is not immediately available, disable nested virtualization or restrict nested VM usage so that L1 and L2 VMs never migrate between physical CPUs; this prevents the mis‑execution from occurring.
  • As a temporary measure, bind both L1 and L2 VMs to a single physical CPU at configuration time, reducing the window in which INVVPID could be mis‑executed.

Generated by OpenCVE AI on September 18, 2026 at 08:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-704

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU When emulating INVVPID, KVM executes INVVPID on the physical CPU using vpid02 (instead of the L1 assigned VPID), after doing some validations on the operands. However, it is possible that the physical CPU KVM executes INVVPID on is different from the CPU L2 is running on. For example, in the following scenario: - L2 runs on CPU #1 and exits to L1 (vmx->nested.vmcs02.cpu=1) - L1 migrates to CPU #2 and executes INVVPID - KVM executes INVVPID on CPU #2 - L1 migrates back to CPU #1 and runs L2 (vmx->nested.vmcs02.cpu=1) The TLB entries on CPU #1 are never invalidated, because INVVPID was executed on CPU #2, and vmcs02 never ran on a different pCPU (i.e. vmx_vcpu_load_vmcs() will *not* request KVM_REQ_TLB_FLUSH). Ensure that INVVPID is being executed on the same pCPU that L2 last ran on, and if not, fallback to clearing last_vpid=0 to trigger a full VPID flush on the next nested VM-Enter (as KVM will detect L1 using a different VPID for L2). If L2 ends up running on a different pCPU, KVM will flush the TLB anyway through vmx_vcpu_load_vmcs().
Title KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:17.783Z

Reserved: 2026-09-11T19:38:34.775Z

Link: CVE-2026-89929

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:02.180

Modified: 2026-09-17T10:17:04.940

Link: CVE-2026-89929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:45:07Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-704

    Incorrect Type Conversion or Cast