Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: nVMX: Service local TLB flushes on failed nested VM-Enter

KVM services local TLB flushes on "full" nested VM-Exits (through
__nested_vmx_vmexit()), but not if a nested VM-Enter fails (e.g. due to
failed VMCS checks in nested_vmx_enter_non_root_mode()).

However, it is possible that KVM had queued TLB flushes that need to be
performed, even if the nested VM-Enter was not successful. For example,
if VPID is disabled for L2 (via nested_vmx_transition_tlb_flush(), or if
via the MSR load lists, as the SDM says:

If any MSR is being loaded in such a way that would architecturally
require a TLB flush, the TLBs are updated so that, after VM entry, the
logical processor will not use any translations that were cached before
the transition.

The SDM is unclear about when the TLB flush should occur, and whether or
not a failed VM entry would flush the TLB, so it is safer to always
do the TLB flush in this case.

More concretely, KVM also updates the last VPID L1 used for L2 in
nested_vmx_transition_tlb_flush() (i.e. last_vpid), even if the VM entry
ultimately fails. With the current code, KVM could miss a TLB flush if
L1 changes L2's VPID, then does a failed VM entry followed by a
successful one, as the failed VM entry would update last_vpid but not
actually flush the TLB. Servicing local TLB flushes on failed VM entries
makes sure that the TLB is always flushed when last_vpid is updated.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation and Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

A bug in the Linux kernel’s KVM hypervisor causes local TLB (Translation Lookaside Buffer) entries to be omitted when a nested VM-Enter operation fails. Because the TLB is not flushed, stale address translations can continue to be used, which may allow a malicious guest or attacker with access to the host to read or write memory belonging to other guests or the kernel. The flaw essentially enables a privilege escalation path and potential data leakage for a local attacker with kernel‑level control. The weakness is a classic example of improper state handling leading to insecure behavior, classified as a race‑condition scenario. The vulnerability has a CVSS score of 9.3, reflecting severe confidentiality, integrity, and availability effects.

Affected Systems

All Linux kernel distributions that include the KVM virtual machine monitor are affected, including mainstream varieties of the Linux kernel released by major vendors. Vendors listed as affected are the generic Linux kernels. The flaw is present in any kernel version that has not yet applied the fix found in recent patch commits referenced in the advisory links. No specific version numbers are supplied, so any kernel without the applied patch is vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity. The EPSS score of less than 1% suggests the exploitation probability is currently low, but the flaw remains unlisted in the CISA KEV catalog, which means an active exploit has not yet been recorded. The likely attack vector is a local attack that has the ability to trigger a VM-Enter in KVM; the typical race occurs when an L2 VM attempts nested entry but fails, then a succeeding successful entry occurs while the TLB flush is omitted. Because the flaw touches kernel memory structures, a local privileged adversary can exploit it to subvert isolation between virtual machines, potentially elevating privileges to the host level or leaking sensitive data. The risk is high when KVM is configured for nested virtualization, especially on systems that host multiple untrusted guests.

Generated by OpenCVE AI on September 18, 2026 at 07:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel patch that includes the CVM TLB flush fix.
  • Disable nested virtualization or prevent nested VM-Entry on this host as a temporary safeguard.
  • Restart the host after patching to ensure all VM services are reinitialized with flushed TLB state.

Generated by OpenCVE AI on September 18, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-847

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Service local TLB flushes on failed nested VM-Enter KVM services local TLB flushes on "full" nested VM-Exits (through __nested_vmx_vmexit()), but not if a nested VM-Enter fails (e.g. due to failed VMCS checks in nested_vmx_enter_non_root_mode()). However, it is possible that KVM had queued TLB flushes that need to be performed, even if the nested VM-Enter was not successful. For example, if VPID is disabled for L2 (via nested_vmx_transition_tlb_flush(), or if via the MSR load lists, as the SDM says: If any MSR is being loaded in such a way that would architecturally require a TLB flush, the TLBs are updated so that, after VM entry, the logical processor will not use any translations that were cached before the transition. The SDM is unclear about when the TLB flush should occur, and whether or not a failed VM entry would flush the TLB, so it is safer to always do the TLB flush in this case. More concretely, KVM also updates the last VPID L1 used for L2 in nested_vmx_transition_tlb_flush() (i.e. last_vpid), even if the VM entry ultimately fails. With the current code, KVM could miss a TLB flush if L1 changes L2's VPID, then does a failed VM entry followed by a successful one, as the failed VM entry would update last_vpid but not actually flush the TLB. Servicing local TLB flushes on failed VM entries makes sure that the TLB is always flushed when last_vpid is updated.
Title KVM: nVMX: Service local TLB flushes on failed nested VM-Enter
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:21.918Z

Reserved: 2026-09-11T19:38:34.775Z

Link: CVE-2026-89930

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:02.290

Modified: 2026-09-16T15:18:18.933

Link: CVE-2026-89930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses