← Volver al buscador de CVEs

CVE-2026-46113

Linux Kernel

Descripción

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN The shadow MMU computes GFNs for direct shadow pages using sp->gfn plus the SPTE index. This assumption breaks for shadow paging if the guest page tables are modified between VM entries (similar to commit aad885e77496, -KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE-, 2026-03-27). The flow is as follows: - a PDE is installed for a 2MB mapping, and a page in that area is accessed. KVM creates a kvm_mmu_page consisting of 512 4KB pages; the kvm_mmu_page is marked by FNAME(fetch) as direct-mapped because the guest-s mapping is a huge page (and thus contiguous). - the PDE mapping is changed from outside the guest. - the guest accesses another page in the same 2MB area. KVM installs a new leaf SPTE and rmap entry; the SPTE uses the -correct- GFN (i.e. based on the new mapping, as changed in the previous step) but that GFN is outsi...

CVSS 8.8EPSS 0.154%Riesgo 0.89
Ver fuente
Publicación
2026-05-28 10:16:26
Versiones afectadas
unknown
Tipo
Core software
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Sistemas operativos
Linux