Out-of-bounds read in Linux kernel - CVE-2026-64247
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in hv_is_vp_in_sparse_set() when handling a paravirtual TLB flush for an L2 guest with a copied VP ID from the enlightened VMCS. A local user can provide a crafted VP ID value to cause a denial of service.
The issue can also cause KVM to perform an unnecessary TLB flush for an L2 vCPU.
Affected software
How to mitigate CVE-2026-64247
External References
- https://git.kernel.org/stable/c/4721f8160f17554b003e8928bb61e6c9b2fe92a3
- https://git.kernel.org/stable/c/83c2f52c6a78b1590034e955cff3fe0b052fe4ae
- https://git.kernel.org/stable/c/d18756b12aab30d07794446445c93112e5c69a2e
- https://git.kernel.org/stable/c/e36095d8d922bb26ce860231aacf0cd14edea07c
- https://git.kernel.org/stable/c/f636cf6a1e7b7f40d48d8d08bd5f152aa61dd130