← Back to search

CVE-2026-89932

8.8 HIGH

Published 2026-09-16 · Updated 2026-09-17

AI risk analysis

Summary
This flaw allows an attacker to use stale TLB entries from a previous VM's VPID, potentially leading to data leakage or execution of malicious code.
Exploitability
Exploitation requires L1 to perform a VMXOFF -> VMXON cycle, run an L2, and KVM to reuse a VPID with existing TLB entries, making it moderately difficult.
Blast radius
If exploited, the impact could be high, as it could lead to data leakage or execution of malicious code on the same CPU.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the Linux kernel version 6.1.18 or later.
kernelvmxtlbvpid

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Always flush vpid02 on first use Make sure vpid02 is always flushed on first use by setting last_vpid=0 when allocating vpid02. nested_vmx_transition_tlb_flush() will always detect a VPID change on first VM-Enter after VMXON, because VPID=0 in vmcs12 is not allowed if L1 enables VPID. This avoids using stale TLB entries from a previous lifetime of the VPID, that might have been associated with a different vCPU (or a completely different VM). Note that last_vpid is already being initialized as 0 when the vCPU is created, but it is not reset when vpid02 is freed on VMXOFF. Hence, the problem can only occur if L1 does VMXOFF -> VMXON, runs an L2, and KVM happens to reuse a VPID that has TLB entries on the physical CPU.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.