← Back to search

CVE-2026-64562

8.8 HIGH

Published 2026-08-04 · Updated 2026-08-08

AI risk analysis

Summary
This vulnerability allows an attacker to potentially free a shadow VMCS prematurely, leading to a race condition that could result in the kernel memory being freed while the vCPU is still using it, potentially leading to a denial of service or other kernel-level issues.
Exploitability
Exploitation requires an attacker to have the ability to trigger a vCPU migration while the VMCS is being freed, which is considered moderately difficult and requires specific conditions to be met.
Blast radius
If exploited, the impact is likely to be limited to the specific virtual machine experiencing the issue, potentially leading to a denial of service or kernel panic, but not affecting other systems directly.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 6.1.11 or later.
dosvmkvmkernel

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow VMCS while vmcs01 still points to it. But because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU might migrate before the pointer is cleared and __loaded_vmcs_clear() may then execute VMCLEAR. The VMCS needs to stay attached until its explicit VMCLEAR completes, but then it can be hidden and the page safely freed.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.