Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit

Always check and clear KVM_REQ_GET_NESTED_STATE_PAGES when emulating a
nested VM-Exit to ensure the request is cleared, even when KVM was built
with CONFIG_KVM_HYPERV=n, as KVM subtly relies on the "check" to clear
the flag and thus avoid double-mapping the vmcs12 pages, e.g. if KVM
manages to bail from VM-Enter without processing the request, and then
emulates VMLAUNCH or VMRESUME.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and potential memory corruption due to double-mapping of nested VMCS pages
Action: Patch Immediately
AI Analysis

Impact

The flaw in the Linux kernel KVM implementation causes the flag KVM_REQ_GET_NESTED_STATE_PAGES to remain set after emulating a nested VM‑exit. If this flag is not cleared, subsequent attempts to launch or resume a nested virtual machine can attempt to map the same set of vmcs12 pages twice, leading to memory corruption or a kernel crash. The vulnerability is confined to the hypervisor layer and does not provide an attacker with direct code execution, but it can be leveraged to disrupt services or potentially facilitate further escalation if memory corruption is exploitable.

Affected Systems

All Linux kernel builds that include the KVM subsystem and support nested virtualization are affected. The issue existed in every revision prior to the patch that clears the flag during vm‑exit handling. The known CPE is cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*, indicating all kernel variants.

Risk and Exploitability

The EPSS score is listed as < 1% and the vulnerability is not present in CISA’s KEV catalog, suggesting a low to very low exploitation probability. The attack would need to be performed from within a nested virtual machine or by a privileged user controlling the hypervisor, so the primary vector is a local virtualized environment. No CVSS score is available in the provided data, but the severity is sufficient to warrant patching to prevent denial of service or potential memory-related exploitation.

Generated by OpenCVE AI on September 18, 2026 at 07:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Linux kernel that contains the KVM nested state pages clearing fix.
  • If the latest kernel cannot be installed, disable nested virtualization support (e.g., set /sys/module/kvm_intel/parameters/nested=0 or /sys/module/kvm_amd/parameters/nested=0) before starting virtual machines.
  • Restart the host or reload the KVM module to ensure the flag clearing logic is active, and test with a nested VM to confirm that VM‑exits no longer double‑map vmcs12 pages.

Generated by OpenCVE AI on September 18, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit Always check and clear KVM_REQ_GET_NESTED_STATE_PAGES when emulating a nested VM-Exit to ensure the request is cleared, even when KVM was built with CONFIG_KVM_HYPERV=n, as KVM subtly relies on the "check" to clear the flag and thus avoid double-mapping the vmcs12 pages, e.g. if KVM manages to bail from VM-Enter without processing the request, and then emulates VMLAUNCH or VMRESUME.
Title KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:22.202Z

Reserved: 2026-09-11T19:38:34.776Z

Link: CVE-2026-89931

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:02.427

Modified: 2026-09-16T11:17:02.427

Link: CVE-2026-89931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses