PT-2026-38957 · Linux · Linux Kernel

Published

2026-05-08

·

Updated

2026-05-15

·

CVE-2026-43315

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the KVM nSVM component where a user-triggerable warning occurs in the svm set nested state() function when nested svm load cr3() fails. This condition can be easily triggered from userspace by modifying the CPUID after loading CR3. The KVM ABI allows userspace to set CPUID after SREGS and vice versa, and the system is permissive regarding guest CPUID, making the warning unnecessary as it provides no meaningful protection for the kernel or benefit to the user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-43315

Affected Products

Linux Kernel