CVE-2026-89931
Last modified
CVE-2026-89931 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit Always check and clear KVM_REQ_GET_NESTED_STATE_PAGES when emulating a nested VM-Exit to ensure the request is cleared, even when KVM was built with CONFIG_KVM_HYPERV=n, as KVM subtly relies on the "check" to clear the flag and thus avoid double-mapping the vmcs12 pages, e.g. if KVM manages to bail from VM-Enter without processing the request, and then emulates VMLAUNCH or VMRESUME..
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit Always check and clear KVM_REQ_GET_NESTED_STATE_PAGES when emulating a nested VM-Exit to ensure the request is cleared, even when KVM was built with CONFIG_KVM_HYPERV=n, as KVM subtly relies on the "check" to clear the flag and thus avoid double-mapping the vmcs12 pages, e.g. if KVM manages to bail from VM-Enter without processing the request, and then emulates VMLAUNCH or VMRESUME.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= b4f69df0f65e97fec439130a0d0a8b9c7cc02df2, < ae190f2439ca30067927077bf570d4c5edf07a0f; >= b4f69df0f65e97fec439130a0d0a8b9c7cc02df2, < 674a3244f07f323f21a106a7bdcaebb6db6a5058; >= b4f69df0f65e97fec439130a0d0a8b9c7cc02df2, < bbec4adc2f340d85f4a77a9ddcddaa6b1f4639c5; >= b4f69df0f65e97fec439130a0d0a8b9c7cc02df2, < 11722439fb206c88e6f31be54173efa9880b4ccb |
| Linux | Linux | 6.8 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89931?
How severe is CVE-2026-89931?
How do I fix CVE-2026-89931?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89926In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89927In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-89928In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-89929In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-8993D.Launcher 2 component of Slovak eID client ecosystem contai…6.5
- CVE-2026-89930In the Linux kernel, the following vulnerability has been re…9.3
- CVE-2026-89932In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-89933In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89934In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89935In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89936In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89937In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-89931?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
