Skip to content
Rota Nacional

Cyber ·

KVM/x86: flaw can trigger a host panic

A report published on September 29, 2026 describes a host-kernel panic triggerable by a guest virtual machine, reproduced on Linux 6.1.74 and a mainline version predating the fix.

In a message published to the oss-sec feed on September 29, 2026, researcher Jinu Kim reports a host-kernel panic in the KVM shadow MMU for x86. According to the report, a guest virtual machine can trigger the issue; it was reproduced on Linux 6.1.74 and a mainline version predating the fix. The described scenario involves someone with kernel-level control of an L1 VM. The report says that Q35 compatibility SMRAM allows KVM's normal and SMM address spaces to access the same guest backing page.

The report also mentions writes to a nested EPT page directory, but the available excerpt does not identify a fixed version or provide mitigation details. Since the feed content is automatically translated, consult the original message in the oss-sec archive and carefully verify the version, fix status, and recommendations before acting. If you use AI to study or apply the material, share only the technical data needed and omit credentials, personal data, and confidential organizational information.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free