Impact
A logic bug in the Linux kernel KVM module caused the VPID2 identifier to be reused after a VMXOFF without a corresponding TLB flush. This left stale TLB entries from a previous VPID lifetime in place, allowing a nested virtual machine to reference memory that belonged to another vCPU or VM, potentially leading to confidentiality and integrity violations. The flaw is an example of an incorrect modification of a data structure (CWE‑682). The vulnerability was fixed by ensuring that vpid02 is always flushed and the last_vpid counter is reset when a new vCPU is allocated.
Affected Systems
All Linux kernel builds that enable KVM with nested virtualization (nVMX) are affected. The issue arises when a Level‑1 virtual machine uses VMXOFF followed by VMXON and runs a Level‑2 guest that reuses a VPID that still has TLB entries on the host CPU. The kernel version before the patch contains the flaw; the bug has been resolved in the stable tree and is present only in systems running older kernel releases.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is less than 1 %, suggesting a very low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to control or influence a nested VM such that a VPID reuse occurs across a VMXOFF/VMXON cycle, which is a specialized scenario but still considered a potential attack vector if an adversary can run a malicious Level‑1 guest.
OpenCVE Enrichment
Debian DLA
Debian DSA