CVE-2026-43483 Details
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated Explicitly set/clear CR8 write interception when AVIC is (de)activated to fix a bug where KVM leaves the interception enabled after AVIC is activated. E.g. if KVM emulates INIT=>WFS while AVIC is deactivated, CR8 will remain intercepted in perpetuity. On its own, the dangling CR8 intercept is "just" a performance issue, but combined with the TPR sync bug fixed by commit d02e48830e3f ("KVM: SVM: Sync TPR from LAPIC into VMCB::V_TPR even if AVIC is active"), the danging intercept is fatal to Windows guests as the TPR seen by hardware gets wildly out of sync with reality. Note, VMX isn't affected by the bug as TPR_THRESHOLD is explicitly ignored when Virtual Interrupt Delivery is enabled, i.e. when APICv is active in KVM's world. I.e. there's no need to trigger update_cr8_intercept(), this is firmly an SVM implementation flaw/detail. WARN if KVM gets a CR8 write #VMEXIT while AVIC is active, as KVM should never enter the guest with AVIC enabled and CR8 writes intercepted. [Squash fix to avic_deactivate_vmcb. - Paolo]
A vulnerability in the Linux kernel's KVM SVM module relates to improper management of CR8 write interception when AVIC is activated or deactivated. This issue can lead to a performance degradation and, more critically, cause synchronization problems with the Task Priority Register (TPR) for Windows virtual machine guests. The vulnerability arises because KVM fails to clear CR8 write interception after AVIC is activated, leaving it enabled indefinitely. While this dangling interception is primarily a performance concern, it becomes detrimental for Windows guests as the TPR, which is crucial for managing interrupts, becomes misaligned with the actual state, potentially disrupting the guest's operation. The issue is not present in VMX, as APICv active environments do not require such interception.
Users can update to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/01651e7751edbbc0fb4598f8367a3dabcfc8c182 | kernel.org | Patch |
| https://git.kernel.org/stable/c/737410b32bd615b321da4fbeda490351b9af5e8b | kernel.org | Patch |
| https://git.kernel.org/stable/c/816fa1dfae4532e851b1fe6b2434c753ecbd86c7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/87d0f901a9bd8ae6be57249c737f20ac0cace93d | kernel.org | Patch |
| https://git.kernel.org/stable/c/a4123fe5d9122eef9852e4921f7cc463420f30d4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ba3bca40f9f25c053f69413e5f4a41dd0fd762bf | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.7, < 6.1.167 >= 6.2, < 6.6.130 >= 6.7, < 6.12.78 >= 6.13, < 6.18.19 >= 6.19, < 6.19.9 7.0 rc1 7.0 rc2 7.0 rc3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 13, 2026 | New CVE Received | kernel.org |