Linux Kernel KVM Shadow Paging Vulnerability in Direct MMUs

Vulnerability

A vulnerability in the Linux kernel's KVM module for x86 architecture can disrupt shadow paging rules. This issue arises in direct memory management units (MMUs) when a shadow-present Single Page Table Entry (SPTE) is overwritten by another SPTE with a different Page Frame Number (PFN). Although KVM typically prevents such overwrites in response to guest writes, it does not track writes from host userspace, which can violate KVM's shadow paging regulations. The vulnerability has been addressed in the Linux kernel stable tree.

Impact

Exploitation of this vulnerability can lead to improper handling of memory management, potentially allowing for violations of KVM's shadow paging rules, which could disrupt virtual machine operations or cause memory management errors.

Added: Apr 1, 2026, 9:29 AM
Updated: Apr 1, 2026, 9:29 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
3.5
remediation
7.7
relevance
5.1
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.