PT-2026-38957 · Linux · Linux Kernel
Published
2026-05-08
·
Updated
2026-05-15
·
CVE-2026-43315
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the KVM nSVM component where a user-triggerable warning occurs in the
svm set nested state() function when nested svm load cr3() fails. This condition can be easily triggered from userspace by modifying the CPUID after loading CR3. The KVM ABI allows userspace to set CPUID after SREGS and vice versa, and the system is permissive regarding guest CPUID, making the warning unnecessary as it provides no meaningful protection for the kernel or benefit to the user.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel