CVE-2026-89932
CVE CVE-2026-89932EUVD EUVD-2026-80532Published 2026-09-16T10:32:22.000ZLast changed 2026-09-17T09:29:18.000ZCVSS 8.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Always flush vpid02 on first use Make sure vpid02 is always flushed on first use by setting last_vpid=0 when allocating vpid02. nested_vmx_transition_tlb_flush() will always detect a VPID change on first VM-Enter after VMXON, because VPID=0 in vmcs12 is not allowed if L1 enables VPID. This avoids using stale TLB entries from a previous lifetime of the VPID, that might have been associated with a different vCPU (or a completely different VM). Note that last_vpid is already being initialized as 0 when the vCPU is created, but it is not reset when vpid02 is freed on VMXOFF. Hence, the problem can only occur if L1 does VMXOFF -> VMXON, runs an L2, and KVM happens to reuse a VPID that has TLB entries on the physical CPU.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 5.15.221; 5c614b3583e7b6dab0c86356fa36c2bcbb8322a0 <26de0d2d9a8d14c03e5ebb25fd68b5bfcd5ac366; patch: 0; patch: 6.12.110; 5c614b3583e7b6dab0c86356fa36c2bcbb8322a0 <8bc609999ec223089fec8d74c7de27d689606b36; 5c614b3583e7b6dab0c86356fa36c2bcbb8322a0 <121991d150735f3c0f7401678ce4d35c5b4ac898; patch: 6.18.51; 5c614b3583e7b6dab0c86356fa36c2bcbb8322a0 <f0772389413dce9657c7d6950abf3edbbd511356; 4.4; patch: 6.1.188; 5c614b3583e7b6dab0c86356fa36c2bcbb8322a0 <22dfcc22c95e91295119a1c3b469816ce44c4804; patch: 6.6.157; 5c614b3583e7b6dab0c86356fa36c2bcbb8322a0 <62604376c313178811375f40a282fc2a46cd2311; patch: 7.2.5; 5c614b3583e7b6dab0c86356fa36c2bcbb8322a0 <8b98d662ab24f34710a56e03bc9169e4a5508606; patch: 7.3-rc1
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.