PT-2026-40690 · Linux+2 · Linux Kernel+2

CVE-2026-43483

·

Published

2026-05-13

·

Updated

2026-08-23

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the KVM SVM implementation where CR8 write interception remains enabled after AVIC (Advanced Virtual Interrupt Controller) is activated. This occurs because the interception is not explicitly cleared during AVIC activation. While this typically results in a performance degradation, it can be fatal for Windows guests when combined with a TPR (Task Priority Register) synchronization bug, causing the TPR seen by the hardware to become out of sync. The flaw is specific to SVM and does not affect VMX.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-43483
OESA-2026-2493
OESA-2026-2494
OESA-2026-2495
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:22108-1
SUSE-SU-2026:22137-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:2482-1
SUSE-SU-2026:2591-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu