https://seclists.org/oss-sec/2026/q3/978: Linux KVM/x86 (tested on 6.1.74): guest-trigged host panic via SMM shadow MMU
Published Sep 29, 2026
·Updated
Affected Software
1 affected component
Linux KVM>=6.1.74<6.1.187, <7.2
Frequently Asked Questions
1
Who can trigger the host panic?
An attacker needs kernel-level control of an L1 guest. The reported reproducer uses nested VMX/EPT, Q35 SMM, and two vCPUs.
2
What host and guest configuration is involved?
The issue depends on Q35 compatibility SMRAM allowing the normal and SMM KVM address spaces to access the same backing guest page. The affected flow write-tracks a nested-EPT page directory in a normal-address-space memslot and modifies it through an SMI handler in SMM.
3
What is the observed impact?
On the tested Linux 6.1.74 host, the condition reaches a BUG() in pte_list_remove() and causes a fatal host-kernel panic. The report also states that the issue was reproduced on pre-fix mainline.