Impact
The flaw in the Linux kernel KVM implementation causes the flag KVM_REQ_GET_NESTED_STATE_PAGES to remain set after emulating a nested VM‑exit. If this flag is not cleared, subsequent attempts to launch or resume a nested virtual machine can attempt to map the same set of vmcs12 pages twice, leading to memory corruption or a kernel crash. The vulnerability is confined to the hypervisor layer and does not provide an attacker with direct code execution, but it can be leveraged to disrupt services or potentially facilitate further escalation if memory corruption is exploitable.
Affected Systems
All Linux kernel builds that include the KVM subsystem and support nested virtualization are affected. The issue existed in every revision prior to the patch that clears the flag during vm‑exit handling. The known CPE is cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*, indicating all kernel variants.
Risk and Exploitability
The EPSS score is listed as < 1% and the vulnerability is not present in CISA’s KEV catalog, suggesting a low to very low exploitation probability. The attack would need to be performed from within a nested virtual machine or by a privileged user controlling the hypervisor, so the primary vector is a local virtualized environment. No CVSS score is available in the provided data, but the severity is sufficient to warrant patching to prevent denial of service or potential memory-related exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA