PT-2025-49486 · Linux+1 · Linux Kernel+1

Published

2025-12-08

·

Updated

2025-12-10

·

CVE-2023-53756

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the KVM component, specifically related to nested hypervisor operation on Hyper-V. The issue stems from an uninitialized current vmcs variable within the evmcs touch msr bitmap function, leading to a potential crash when updating the MSR bitmap. This occurs because the code may incorrectly write to memory pointed to by an uninitialized current vmcs value, particularly during preemption scenarios. The root cause is the insufficient check for current vmcs being null. The issue is triggered by calls to vmx disable intercept for msr and vmx vcpu create. The crash manifests as a kernel NULL pointer dereference.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2023-53756
RHSA-2023:3465
RHSA-2023:6583

Affected Products

Hyper-V
Linux Kernel