Impact
A bug in the Linux kernel’s KVM hypervisor causes local TLB (Translation Lookaside Buffer) entries to be omitted when a nested VM-Enter operation fails. Because the TLB is not flushed, stale address translations can continue to be used, which may allow a malicious guest or attacker with access to the host to read or write memory belonging to other guests or the kernel. The flaw essentially enables a privilege escalation path and potential data leakage for a local attacker with kernel‑level control. The weakness is a classic example of improper state handling leading to insecure behavior, classified as a race‑condition scenario. The vulnerability has a CVSS score of 9.3, reflecting severe confidentiality, integrity, and availability effects.
Affected Systems
All Linux kernel distributions that include the KVM virtual machine monitor are affected, including mainstream varieties of the Linux kernel released by major vendors. Vendors listed as affected are the generic Linux kernels. The flaw is present in any kernel version that has not yet applied the fix found in recent patch commits referenced in the advisory links. No specific version numbers are supplied, so any kernel without the applied patch is vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score of less than 1% suggests the exploitation probability is currently low, but the flaw remains unlisted in the CISA KEV catalog, which means an active exploit has not yet been recorded. The likely attack vector is a local attack that has the ability to trigger a VM-Enter in KVM; the typical race occurs when an L2 VM attempts nested entry but fails, then a succeeding successful entry occurs while the TLB flush is omitted. Because the flaw touches kernel memory structures, a local privileged adversary can exploit it to subvert isolation between virtual machines, potentially elevating privileges to the host level or leaking sensitive data. The risk is high when KVM is configured for nested virtualization, especially on systems that host multiple untrusted guests.
OpenCVE Enrichment
Debian DLA
Debian DSA