Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-43265

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
06/05/2026
Última modificación:
08/05/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block()<br /> <br /> Ignore -EBUSY when checking nested events after exiting a blocking state<br /> while L2 is active, as exiting to userspace will generate a spurious<br /> userspace exit, usually with KVM_EXIT_UNKNOWN, and likely lead to the VM&amp;#39;s<br /> demise. Continuing with the wakeup isn&amp;#39;t perfect either, as *something*<br /> has gone sideways if a vCPU is awakened in L2 with an injected event (or<br /> worse, a nested run pending), but continuing on gives the VM a decent<br /> chance of surviving without any major side effects.<br /> <br /> As explained in the Fixes commits, it _should_ be impossible for a vCPU to<br /> be put into a blocking state with an already-injected event (exception,<br /> IRQ, or NMI). Unfortunately, userspace can stuff MP_STATE and/or injected<br /> events, and thus put the vCPU into what should be an impossible state.<br /> <br /> Don&amp;#39;t bother trying to preserve the WARN, e.g. with an anti-syzkaller<br /> Kconfig, as WARNs can (hopefully) be added in paths where _KVM_ would be<br /> violating x86 architecture, e.g. by WARNing if KVM attempts to inject an<br /> exception or interrupt while the vCPU isn&amp;#39;t running.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1 (incluyendo) 6.1.167 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.130 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.77 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.17 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 6.19.6 (excluyendo)