With shadow paging enabled, the INVPCID instruction results in a call to kvmmmuinvpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference.
{ "urgency": "not yet assigned" }