PT-2026-90890 · Azure Linux · Kernel

Published

2026-09-03

·

Updated

2026-09-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
Explicitly clear role.invalid when deriving a child shadow page's role from its parent to harden against bugs elsewhere in KVM, as violating KVM's invariant that invalid pages are NOT on the list of active MMU pages leads to use-after-free due to kvm mmu prepare zap page() using list add() instead of list move() when processing an invalid shadow page, i.e. makes a bad situation far worse.
Yell loudly if the parent is invalid, as it means KVM has missed a validity check, i.e. KVM is attempting to map memory using an invalid/obsolete root, but continue on as the child is otherwise still a valid shadow page.
================================================================== BUG: KASAN: slab-use-after-free in kvm mmu get shadow page+0x1817/0x1860 [kvm] Write of size 8 at addr ff11000153dd1368 by task repro/853
CPU: 1 UID: 1000 PID: 853 Comm: repro Not tainted 7.2.0-rc2-3aec122bdcaf-next-vm #5 PREEMPT Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 Call Trace: dump stack lvl+0x4b/0x70 print report+0x153/0x49c kasan report+0xbc/0xf0 kvm mmu get shadow page+0x1817/0x1860 [kvm] mmu alloc root+0x141/0x320 [kvm] kvm mmu load+0x612/0x20f0 [kvm] kvm arch vcpu ioctl run+0x3dd5/0x6150 [kvm] kvm vcpu ioctl+0x5e4/0x10d0 [kvm] x64 sys ioctl+0x131/0x1b0 do syscall 64+0x67/0x5f0 entry SYSCALL 64 after hwframe+0x4b/0x53
Allocated by task 853: kasan save stack+0x20/0x40 kasan save track+0x14/0x30 kasan slab alloc+0x5f/0x70 kmem cache alloc noprof+0xfe/0x2e0 kvm mmu topup memory cache+0x135/0x530 [kvm] paging64 page fault+0x318/0x1e30 [kvm] kvm mmu do page fault+0x21d/0x630 [kvm] kvm mmu page fault+0x18c/0x17b0 [kvm] kvm arch vcpu ioctl run+0x1f35/0x6150 [kvm] kvm vcpu ioctl+0x5e4/0x10d0 [kvm] x64 sys ioctl+0x131/0x1b0 do syscall 64+0x67/0x5f0 entry SYSCALL 64 after hwframe+0x4b/0x53
Freed by task 853: kasan save stack+0x20/0x40 kasan save track+0x14/0x30 kasan save free info+0x3b/0x60 kasan slab free+0x43/0x70 kmem cache free+0xe2/0x400 kvm mmu commit zap page.part.0+0x1e2/0x310 [kvm] kvm mmu free roots+0x283/0x560 [kvm] kvm arch vcpu ioctl run+0x33c8/0x6150 [kvm] kvm vcpu ioctl+0x5e4/0x10d0 [kvm] x64 sys ioctl+0x131/0x1b0 do syscall 64+0x67/0x5f0 entry SYSCALL 64 after hwframe+0x4b/0x53
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-99062

Affected Products

Kernel