CVE-2026-89931
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-89931, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-16
Last updated on: 2026-09-16
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit
Always check and clear KVM_REQ_GET_NESTED_STATE_PAGES when emulating a
nested VM-Exit to ensure the request is cleared, even when KVM was built
with CONFIG_KVM_HYPERV=n, as KVM subtly relies on the "check" to clear
the flag and thus avoid double-mapping the vmcs12 pages, e.g. if KVM
manages to bail from VM-Enter without processing the request, and then
emulates VMLAUNCH or VMRESUME.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | b4f69df0f65e97fec439130a0d0a8b9c7cc02df2 |
| Linux | Linux | b4f69df0f65e97fec439130a0d0a8b9c7cc02df2 |
| Linux | Linux | b4f69df0f65e97fec439130a0d0a8b9c7cc02df2 |
| Linux | Linux | b4f69df0f65e97fec439130a0d0a8b9c7cc02df2 |
| Linux | Linux | 6.8 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |