๐Ÿ” CVE Alert

CVE-2026-64604

UNKNOWN 0.0

KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8 intercepts, get vmcs12 if and only if the vCPU is in guest mode so that a future change can have update CR8 intercepts during vCPU creation, without running afoul of get_vmcs12()'s lockdep assertion. ------------[ cut here ]------------ debug_locks && !(lock_is_held(&(&vcpu->mutex)->dep_map) || !refcount_read(&vcpu->kvm->users_count)) WARNING: arch/x86/kvm/vmx/nested.h:61 at get_vmcs12 arch/x86/kvm/vmx/nested.h:60 [inline], CPU#0: syz.2.19/5879 WARNING: arch/x86/kvm/vmx/nested.h:61 at vmx_update_cr8_intercept+0x3de/0x4e0 arch/x86/kvm/vmx/vmx.c:6879, CPU#0: syz.2.19/5879 Modules linked in: CPU: 0 UID: 0 PID: 5879 Comm: syz.2.19 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 RIP: 0010:get_vmcs12 arch/x86/kvm/vmx/nested.h:60 [inline] RIP: 0010:vmx_update_cr8_intercept+0x3de/0x4e0 arch/x86/kvm/vmx/vmx.c:6879 Call Trace: <TASK> apic_update_ppr arch/x86/kvm/lapic.c:984 [inline] kvm_lapic_reset+0x1c24/0x2980 arch/x86/kvm/lapic.c:3023 kvm_vcpu_reset+0x44c/0x1bf0 arch/x86/kvm/x86.c:12986 kvm_arch_vcpu_create+0x746/0x8b0 arch/x86/kvm/x86.c:12847 kvm_vm_ioctl_create_vcpu+0x428/0x930 virt/kvm/kvm_main.c:4201 kvm_vm_ioctl+0x893/0xd50 virt/kvm/kvm_main.c:5159 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:583 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f </TASK> No functional change intended.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c7cd3605244c924249dea32632e1bc3e89bda543 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9a21f1defd96c6301c5fb462a78eb51b191bd2dd 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 570af5db081b87374594a00711ac5760d2ea6844 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ffaaff82336db84e9b58e7a3e81c2fd64e05ed7a 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 258ec63c0f281bf7b50f9de67c8e93b5b7be5ed4 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3dcfb04dd43b16fa1240fc6487fff578ad57264c 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < db8407b9fd06d857a4a5e8bcff1d086d13007711 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7ef78d71ca713d8c00f7c34ddcf276c808143f77 0 < 5.10.261 0 < 5.15.212 0 < 6.1.178 0 < 6.6.145 0 < 6.12.96 0 < 6.18.39 0 < 7.1.4
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c7cd3605244c924249dea32632e1bc3e89bda543 git.kernel.org: https://git.kernel.org/stable/c/9a21f1defd96c6301c5fb462a78eb51b191bd2dd git.kernel.org: https://git.kernel.org/stable/c/570af5db081b87374594a00711ac5760d2ea6844 git.kernel.org: https://git.kernel.org/stable/c/ffaaff82336db84e9b58e7a3e81c2fd64e05ed7a git.kernel.org: https://git.kernel.org/stable/c/258ec63c0f281bf7b50f9de67c8e93b5b7be5ed4 git.kernel.org: https://git.kernel.org/stable/c/3dcfb04dd43b16fa1240fc6487fff578ad57264c git.kernel.org: https://git.kernel.org/stable/c/db8407b9fd06d857a4a5e8bcff1d086d13007711 git.kernel.org: https://git.kernel.org/stable/c/7ef78d71ca713d8c00f7c34ddcf276c808143f77