« Volver al listado

CVE-2026-89932

Estado: RecibidaAlta (8.8)—

In the Linux kernel, the following vulnerability has been resolved:

KVM: nVMX: Always flush vpid02 on first use

Make sure vpid02 is always flushed on first use by setting last_vpid=0 when allocating vpid02. nested_vmx_transition_tlb_flush() will always detect a VPID change on first VM-Enter after VMXON, because VPID=0 in vmcs12 is not allowed if L1 enables VPID.

This avoids using stale TLB entries from a previous lifetime of the VPID, that might have been associated with a different vCPU (or a completely different VM).

Note that last_vpid is already being initialized as 0 when the vCPU is created, but it is not reset when vpid02 is freed on VMXOFF.

Leer descripción completaMostrar menos

Hence, the problem can only occur if L1 does VMXOFF -> VMXON, runs an L2, and KVM happens to reuse a VPID that has TLB entries on the physical CPU.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de escalada de privilegios en KVM/nVMX que permite a un atacante local con privilegios acceder a entradas TLB obsoletas de VPIDs reutilizados, causando fuga de datos entre máquinas virtuales o deniego de servicio por manipulación de memoria.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89932",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5c614b3583e7b6dab0c86356fa36c2bcbb8322a0",
              "lessThan": "26de0d2d9a8d14c03e5ebb25fd68b5bfcd5ac366",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c614b3583e7b6dab0c86356fa36c2bcbb8322a0",
              "lessThan": "8bc609999ec223089fec8d74c7de27d689606b36",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c614b3583e7b6dab0c86356fa36c2bcbb8322a0",
              "lessThan": "62604376c313178811375f40a282fc2a46cd2311",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c614b3583e7b6dab0c86356fa36c2bcbb8322a0",
              "lessThan": "8b98d662ab24f34710a56e03bc9169e4a5508606",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c614b3583e7b6dab0c86356fa36c2bcbb8322a0",
              "lessThan": "22dfcc22c95e91295119a1c3b469816ce44c4804",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c614b3583e7b6dab0c86356fa36c2bcbb8322a0",
              "lessThan": "121991d150735f3c0f7401678ce4d35c5b4ac898",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5c614b3583e7b6dab0c86356fa36c2bcbb8322a0",
              "lessThan": "f0772389413dce9657c7d6950abf3edbbd511356",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/x86/kvm/vmx/nested.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/x86/kvm/vmx/nested.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:02.543",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/121991d150735f3c0f7401678ce4d35c5b4ac898",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/22dfcc22c95e91295119a1c3b469816ce44c4804",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/26de0d2d9a8d14c03e5ebb25fd68b5bfcd5ac366",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/62604376c313178811375f40a282fc2a46cd2311",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8b98d662ab24f34710a56e03bc9169e4a5508606",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8bc609999ec223089fec8d74c7de27d689606b36",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f0772389413dce9657c7d6950abf3edbbd511356",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nVMX: Always flush vpid02 on first use\n\nMake sure vpid02 is always flushed on first use by setting last_vpid=0\nwhen allocating vpid02.  nested_vmx_transition_tlb_flush() will always\ndetect a VPID change on first VM-Enter after VMXON, because VPID=0 in\nvmcs12 is not allowed if L1 enables VPID.\n\nThis avoids using stale TLB entries from a previous lifetime of the\nVPID, that might have been associated with a different vCPU (or a\ncompletely different VM).\n\nNote that last_vpid is already being initialized as 0 when the vCPU is\ncreated, but it is not reset when vpid02 is freed on VMXOFF. Hence, the\nproblem can only occur if L1 does VMXOFF -> VMXON, runs an L2, and KVM\nhappens to reuse a VPID that has TLB entries on the physical CPU."
    }
  ],
  "lastModified": "2026-09-17T10:17:05.073",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}