CVE-2026-23402

Source
https://cve.org/CVERecord?id=CVE-2026-23402
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23402.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23402
Downstream
Published
2026-04-01T08:36:33.366Z
Modified
2026-08-12T03:51:18.063035787Z
Summary
KVM: x86/mmu: Only WARN in direct MMUs when overwriting shadow-present SPTE
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86/mmu: Only WARN in direct MMUs when overwriting shadow-present SPTE

Adjust KVM's sanity check against overwriting a shadow-present SPTE with a another SPTE with a different target PFN to only apply to direct MMUs, i.e. only to MMUs without shadowed gPTEs. While it's impossible for KVM to overwrite a shadow-present SPTE in response to a guest write, writes from outside the scope of KVM, e.g. from host userspace, aren't detected by KVM's write tracking and so can break KVM's shadow paging rules.

------------[ cut here ]------------ pfn != sptetopfn(*sptep) WARNING: arch/x86/kvm/mmu/mmu.c:3069 at mmusetspte+0x1e4/0x440 [kvm], CPU#0: vmxeptstaler/872 Modules linked in: kvmintel kvm irqbypass CPU: 0 UID: 1000 PID: 872 Comm: vmxeptstaler Not tainted 7.0.0-rc2-eafebd2d2ab0-sink-vm #319 PREEMPT Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 RIP: 0010:mmusetspte+0x1e4/0x440 [kvm] Call Trace: <TASK> eptpagefault+0x535/0x7f0 [kvm] kvmmmudopagefault+0xee/0x1f0 [kvm] kvmmmupagefault+0x8d/0x620 [kvm] vmxhandleexit+0x18c/0x5a0 [kvmintel] kvmarchvcpuioctlrun+0xc55/0x1c20 [kvm] kvmvcpu_ioctl+0x2d5/0x980 [kvm] __x64sysioctl+0x8a/0xd0 dosyscall64+0xb5/0x730 entrySYSCALL64afterhwframe+0x4b/0x53 </TASK> ---[ end trace 0000000000000000 ]---

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23402.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
11d45175111d933c5175acc28e56af2213dd5cd6
Fixed
bab090e8fd5607f77379ea78b9d0c683cb1538a9
Fixed
a1e0f7150639bc30a8e75476d1c7daab77d44992
Fixed
df83746075778958954aa0460cca55f4b3fc9c02

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23402.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.18.21
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23402.json"