CVE-2026-64561
CVE CVE-2026-64561EUVD EUVD-2026-52602Published 2026-08-04T06:23:21.000ZLast changed 2026-08-09T03:38:12.000ZCVSS 8.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 5.9; patch: 0; f95eec9bed76d42194c23153cb1cc8f186bf91cb <bce0d3c26e2c761a4bf43c8949f333fc7374eb2d; patch: 6.18.42; patch: 7.1.6; f95eec9bed76d42194c23153cb1cc8f186bf91cb <0026dbb7de8ea76e97d6edf42fc3cc084564e2bf; f95eec9bed76d42194c23153cb1cc8f186bf91cb <f3477a6a4164f15287444eda685b5f6405dbd1e5; patch: 6.12.101; f95eec9bed76d42194c23153cb1cc8f186bf91cb <35e77467610c4a37cb0ff54ee56b85f73b1f5700; patch: 7.2-rc5; patch: 6.6.148; f95eec9bed76d42194c23153cb1cc8f186bf91cb <2abd5287f08319fa35764566b15c6e22cb1068db
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.