CVE-2026-89931

Source
https://cve.org/CVERecord?id=CVE-2026-89931
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89931.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89931
Downstream
Published
2026-09-16T10:32:22Z
Modified
2026-09-18T03:48:34Z
Summary
KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit

Always check and clear KVM_REQ_GET_NESTED_STATE_PAGES when emulating a nested VM-Exit to ensure the request is cleared, even when KVM was built with CONFIG_KVM_HYPERV=n, as KVM subtly relies on the "check" to clear the flag and thus avoid double-mapping the vmcs12 pages, e.g. if KVM manages to bail from VM-Enter without processing the request, and then emulates VMLAUNCH or VMRESUME.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89931.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b4f69df0f65e97fec439130a0d0a8b9c7cc02df2
Fixed
ae190f2439ca30067927077bf570d4c5edf07a0f
Fixed
674a3244f07f323f21a106a7bdcaebb6db6a5058
Fixed
bbec4adc2f340d85f4a77a9ddcddaa6b1f4639c5
Fixed
11722439fb206c88e6f31be54173efa9880b4ccb

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89931.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89931.json"