CVE-2026-43133: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation

Published May 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation

Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload of guest state") made KVM always use vmcb01 for the fields controlled by VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code to always use vmcb01.

As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01 instead of the current VMCB.

Affected Software

7 affected components
Linux Linux kernel
Linux Linux kernel>=5.13<5.15.202
Linux Linux kernel>=5.16<6.1.165
Linux Linux kernel>=6.2<6.6.128
Linux Linux kernel>=6.7<6.12.75
Linux Linux kernel>=6.13<6.18.16
Linux Linux kernel>=6.19<6.19.6

Event History

May 6, 2026
CVE Published
via MITRE·11:27 AM
Data Sourced
via MITRE·11:27 AM
DescriptionSeverity
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·01:02 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

The issue applies to Linux kernel KVM deployments using nested SVM (nSVM). The affected path is reached when an L2 guest executes VMSAVE or VMLOAD and L1 does not intercept that instruction.

2

What access or conditions are required for exploitation?

An attacker needs local, low-complexity access in an affected nested-virtualization environment. They must be able to cause an L2 guest to execute VMSAVE or VMLOAD without interception by the L1 guest.

3

What should operators do if they cannot immediately patch?

No temporary mitigation is specified in the provided data. The described trigger depends on L2 execution of VMLOAD or VMSAVE without L1 interception, so limiting that condition can reduce exposure until a kernel containing the referenced stable fixes is deployed.

4

How can I determine whether a system is affected?

Check whether the system runs the Linux kernel with KVM nested SVM enabled and hosts nested guests. The provided data does not identify affected kernel version ranges, so compare the deployed kernel's fixes against the referenced stable commits rather than relying on a version number.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203