Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4505 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-64561PATCHED
linux · linux kernel

KVM: x86: Check for invalid/obsolete root *after* making MMU pages available

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.

Affected Products

VendorProductVersions
linuxlinux kernelf95eec9bed76d42194c23153cb1cc8f186bf91cb, f95eec9bed76d42194c23153cb1cc8f186bf91cb, f95eec9bed76d42194c23153cb1cc8f186bf91cb, f95eec9bed76d42194c23153cb1cc8f186bf91cb, f95eec9bed76d42194c23153cb1cc8f186bf91cb, f95eec9bed76d42194c23153cb1cc8f186bf91cb, f95eec9bed76d42194c23153cb1cc8f186bf91cb, 5.9

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourceopen source linux kernelcert_advisory90%

References

  • https://git.kernel.org/stable/c/62ef67af1878fa2cd066642f2f59e33ade95f637
  • https://git.kernel.org/stable/c/65c4f7a1028cf01a93a2762d679c289810ede990
  • https://git.kernel.org/stable/c/35e77467610c4a37cb0ff54ee56b85f73b1f5700
  • https://git.kernel.org/stable/c/0026dbb7de8ea76e97d6edf42fc3cc084564e2bf
  • https://git.kernel.org/stable/c/f3477a6a4164f15287444eda685b5f6405dbd1e5
  • https://git.kernel.org/stable/c/bce0d3c26e2c761a4bf43c8949f333fc7374eb2d
  • https://git.kernel.org/stable/c/2abd5287f08319fa35764566b15c6e22cb1068db
  • https://github.com/V4bel/Zapscape

Related News (17 articles)

Tier B
CERT-FR3d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (25 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR10d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (18 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR10d ago
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (18 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans le noyau Linux de Debian LTS (11 septembre 2026)
→ No new info (linked only)
Tier B
CERT-FR31d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (28 août 2026)
→ No new info (linked only)
Tier B
CERT-FR38d ago
Multiples vulnérabilités dans le noyau Linux de Debian LTS (21 août 2026)
→ No new info (linked only)
Tier B
CERT-FR38d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (21 août 2026)
→ No new info (linked only)
Tier B
CERT-FR45d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (14 août 2026)
→ No new info (linked only)
Tier B
CERT-FR45d ago
Multiples vulnérabilités dans le noyau Linux de Debian (14 août 2026)
→ No new info (linked only)
Tier D
The Hacker News48d ago
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
→ No new info (linked only)
Tier A
Microsoft MSRC49d ago
CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
→ No new info (linked only)
Tier D
The Hacker News52d ago
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
→ No new info (linked only)
Tier E
Lobsters Security52d ago
Zapscape - Guest to host escape in KVM/x86
→ No new info (linked only)
Tier C
oss-security52d ago
Zapscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-64561)
→ No new info (linked only)
Tier B
BSI Advisories54d ago
[NEU] [hoch] Linux Kernel: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB54d ago
CVE-2026-64561 | Linux Kernel up to 7.2-rc4 KVM memory corruption
→ No new info (linked only)
Tier C
Linux Kernel CVEs54d ago
CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
35e77467610c4a37cb0ff54ee56b85f73b1f57000026dbb7de8ea76e97d6edf42fc3cc084564e2bff3477a6a4164f15287444eda685b5f6405dbd1e5bce0d3c26e2c761a4bf43c8949f333fc7374eb2d2abd5287f08319fa35764566b15c6e22cb1068db06.6.1486.12.1016.18.427.1.67.2-rc5
PublishedAug 4, 2026
Trending Score43
Source articles17
Independent8
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-53362EXPKEV
ipv6: account for fraggap on the paged allocation path
Trending: 93
HIGHCVE-2026-53359EXP
KVM: x86: Fix shadow paging use-after-free due to unexpected role
Trending: 63
HIGHCVE-2026-53366EXP
ipv4: account for fraggap on the paged allocation path
Trending: 49
HIGHCVE-2026-53360EXP
KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use
Trending: 46
HIGHCVE-2026-64581EXP
xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
Trending: 44

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 4, 2026
Discovered by ZDM
Aug 4, 2026
Patch Available
Aug 27, 2026