{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-64561", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-07-19T15:36:31.796Z", "datePublished": "2026-08-04T06:23:21.094Z", "dateUpdated": "2026-08-04T06:23:21.094Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-04T06:23:21.094Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Check for invalid/obsolete root *after* making MMU pages available\n\nCheck for a \"stale\" page fault, i.e. for an invalid and/or obsolete root,\nafter making MMU pages available for the shadow MMU. If reclaiming shadow\npages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to\nmap memory into an invalid root. On its own, populating an invalid root is\n\"fine\", but because child shadow pages inherit their parent's role, any\nchildren created during the map/fetch will be created as invalid pages,\nthus violating KVM's invariant that invalid pages are never on the list of\nactive MMU pages.\n\nNote, the underlying flaw has existed since KVM first started tracking\ninvalid roots in 2008 (commit 2e53d63acba7, \"KVM: MMU: ignore zapped root\npagetables\"), but the true badness only came along in 2020 (Linux 5.9)\nwith the invariant that invalid shadow pages can't be on the list of\nactive pages.\n\nNote #2, inheriting role.invalid when creating child shadow pages is also\nfar from ideal; that flaw will be addressed separately." } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "arch/x86/kvm/mmu/mmu.c", "arch/x86/kvm/mmu/paging_tmpl.h" ], "versions": [ { "version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb", "lessThan": "35e77467610c4a37cb0ff54ee56b85f73b1f5700", "status": "affected", "versionType": "git" }, { "version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb", "lessThan": "0026dbb7de8ea76e97d6edf42fc3cc084564e2bf", "status": "affected", "versionType": "git" }, { "version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb", "lessThan": "f3477a6a4164f15287444eda685b5f6405dbd1e5", "status": "affected", "versionType": "git" }, { "version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb", "lessThan": "bce0d3c26e2c761a4bf43c8949f333fc7374eb2d", "status": "affected", "versionType": "git" }, { "version": "f95eec9bed76d42194c23153cb1cc8f186bf91cb", "lessThan": "2abd5287f08319fa35764566b15c6e22cb1068db", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "arch/x86/kvm/mmu/mmu.c", "arch/x86/kvm/mmu/paging_tmpl.h" ], "versions": [ { "version": "5.9", "status": "affected" }, { "version": "0", "lessThan": "5.9", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.148", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.101", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.42", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.1.6", "lessThanOrEqual": "7.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.2-rc5", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.9", "versionEndExcluding": "6.6.148" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.9", "versionEndExcluding": "6.12.101" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.9", "versionEndExcluding": "6.18.42" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.9", "versionEndExcluding": "7.1.6" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.9", "versionEndExcluding": "7.2-rc5" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/35e77467610c4a37cb0ff54ee56b85f73b1f5700" }, { "url": "https://git.kernel.org/stable/c/0026dbb7de8ea76e97d6edf42fc3cc084564e2bf" }, { "url": "https://git.kernel.org/stable/c/f3477a6a4164f15287444eda685b5f6405dbd1e5" }, { "url": "https://git.kernel.org/stable/c/bce0d3c26e2c761a4bf43c8949f333fc7374eb2d" }, { "url": "https://git.kernel.org/stable/c/2abd5287f08319fa35764566b15c6e22cb1068db" } ], "title": "KVM: x86: Check for invalid/obsolete root *after* making MMU pages available", "x_generator": { "engine": "bippy-1.2.0" } } } }