CVE-2026-64604

Source
https://cve.org/CVERecord?id=CVE-2026-64604
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64604.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64604
Downstream
Published
2026-08-06T07:13:55.718Z
Modified
2026-08-08T03:48:18.998287862Z
Summary
KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode

When updating CR8 intercepts, get vmcs12 if and only if the vCPU is in guest mode so that a future change can have update CR8 intercepts during vCPU creation, without running afoul of get_vmcs12()'s lockdep assertion.

------------[ cut here ]------------ debuglocks && !(lockisheld(&(&vcpu->mutex)->depmap) || !refcountread(&vcpu->kvm->userscount)) WARNING: arch/x86/kvm/vmx/nested.h:61 at getvmcs12 arch/x86/kvm/vmx/nested.h:60 [inline], CPU#0: syz.2.19/5879 WARNING: arch/x86/kvm/vmx/nested.h:61 at vmxupdatecr8intercept+0x3de/0x4e0 arch/x86/kvm/vmx/vmx.c:6879, CPU#0: syz.2.19/5879 Modules linked in: CPU: 0 UID: 0 PID: 5879 Comm: syz.2.19 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014 RIP: 0010:getvmcs12 arch/x86/kvm/vmx/nested.h:60 [inline] RIP: 0010:vmxupdatecr8intercept+0x3de/0x4e0 arch/x86/kvm/vmx/vmx.c:6879 Call Trace: <TASK> apicupdateppr arch/x86/kvm/lapic.c:984 [inline] kvmlapicreset+0x1c24/0x2980 arch/x86/kvm/lapic.c:3023 kvmvcpureset+0x44c/0x1bf0 arch/x86/kvm/x86.c:12986 kvmarchvcpucreate+0x746/0x8b0 arch/x86/kvm/x86.c:12847 kvmvmioctlcreatevcpu+0x428/0x930 virt/kvm/kvmmain.c:4201 kvmvmioctl+0x893/0xd50 virt/kvm/kvmmain.c:5159 vfsioctl fs/ioctl.c:51 [inline] __dosysioctl fs/ioctl.c:597 [inline] __sesysioctl+0xfc/0x170 fs/ioctl.c:583 dosyscallx64 arch/x86/entry/syscall64.c:63 [inline] dosyscall64+0x174/0x580 arch/x86/entry/syscall64.c:94 entrySYSCALL64afterhwframe+0x77/0x7f </TASK>

No functional change intended.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64604.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a7c0b07d570848e50fce4d31ac01313484d6b844
Fixed
c7cd3605244c924249dea32632e1bc3e89bda543
Fixed
9a21f1defd96c6301c5fb462a78eb51b191bd2dd
Fixed
570af5db081b87374594a00711ac5760d2ea6844
Fixed
ffaaff82336db84e9b58e7a3e81c2fd64e05ed7a
Fixed
258ec63c0f281bf7b50f9de67c8e93b5b7be5ed4
Fixed
3dcfb04dd43b16fa1240fc6487fff578ad57264c
Fixed
db8407b9fd06d857a4a5e8bcff1d086d13007711
Fixed
7ef78d71ca713d8c00f7c34ddcf276c808143f77

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64604.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.18.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64604.json"