PT-2026-67668 · Linux+1 · Linux Kernel+1

CVE-2026-64561

·

Published

2026-07-13

·

Updated

2026-09-09

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 5.9 and earlier
Description An issue exists in the KVM x86 component where the system fails to check for a stale page fault, specifically an invalid or obsolete root, after making MMU pages available for the shadow MMU. If the process of reclaiming shadow pages marks an in-use root as invalid, KVM may attempt to map memory into that invalid root. Because child shadow pages inherit the role of their parent, any children created during the map or fetch process are also created as invalid pages. This violates the KVM invariant that invalid pages must never be on the list of active MMU pages. This flaw can allow an attacker with guest root privileges to break out of a nested VM and execute code as root on the host when nested virtualization is exposed to untrusted guests.
Recommendations Update the Linux kernel to a version where this issue has been resolved. As a temporary mitigation, avoid exposing nested virtualization to untrusted guests.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:45114
ALSA-2026:45115
ALSA-2026:45116
ALSA-2026:45192
AZL-94368
BDU:2026-11388
CVE-2026-64561
OPENSUSE-SU-2026:11476-1
OPENSUSE-SU-2026:21555-1
RHSA-2026:45114
RHSA-2026:45115
RHSA-2026:45116
RHSA-2026:45192
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3593-1
SUSE-SU-2026:3595-1
SUSE-SU-2026:3602-1
SUSE-SU-2026:3616-1
SUSE-SU-2026:3617-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1

Affected Products

Linux Kernel
Rocky Linux