PT-2026-93570 · Linux · Linux Kernel
CVE-2026-89929
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the KVM nested VM (nVM) implementation where the INVVPID instruction may be emulated on an incorrect physical CPU. When emulating INVVPID, KVM uses
vpid02 on the current physical CPU; however, if the L1 guest has migrated to a different physical CPU than the one where L2 last ran, the Translation Lookaside Buffer (TLB) entries on the original CPU are not invalidated. This occurs because vmx vcpu load vmcs() may not request a KVM REQ TLB FLUSH if the L2 guest is perceived to be running on the same physical CPU it previously occupied, despite the invalidation command having been executed elsewhere.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel