In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state… (CVE-2026-68081)
A vulnerability in the Linux kernel's KVM nested virtualization implementation was resolved. The issue involved failure to release (put) vmcs12 pages when nested VM-Enter fails due to an invalid guest state during emulation of VMLAUNCH or VMRESUME. This could lead to resource leaks of pinned pages or mappings if the L1 hypervisor retries these operations. The problem does not affect scenarios where the nested VM-Enter is not involved, as vmcs12 pages are only pinned if L2 is active.
AI Analysis
Technical Summary
The Linux kernel KVM nested virtualization code did not properly release vmcs12 pages when a nested VM-Enter operation failed due to an invalid guest state. Specifically, when KVM synthesizes a nested VM-Exit during emulation of VMLAUNCH or VMRESUME, the code path that handles invalid guest states bypassed the nested_vmx_vmexit() API, which is responsible for releasing vmcs12 pages. This omission caused pinned pages and/or mappings to leak if the L1 hypervisor retried the VM-Enter operation. The issue was fixed by ensuring all vmcs12 pages are put in this failure path. The problem does not occur in non-VM-Enter scenarios because vmcs12 pages are only pinned if L2 is active, guaranteeing a full VM-Exit before retrying.
Potential Impact
The vulnerability could cause resource leaks of pinned memory pages or mappings in the KVM nested virtualization environment when nested VM-Enter fails due to invalid guest state. This may lead to increased memory usage and potential stability or performance degradation on the host running nested virtual machines. There is no indication of direct code execution or privilege escalation from this issue.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to ensure vmcs12 pages are properly released when nested VM-Enter fails due to invalid guest state. Users should update to the fixed kernel version once available. Patch status is not explicitly confirmed in the provided data; therefore, check the official Linux kernel advisories or vendor updates for the exact fixed versions and apply them accordingly.
In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state… (CVE-2026-68081)
Description
A vulnerability in the Linux kernel's KVM nested virtualization implementation was resolved. The issue involved failure to release (put) vmcs12 pages when nested VM-Enter fails due to an invalid guest state during emulation of VMLAUNCH or VMRESUME. This could lead to resource leaks of pinned pages or mappings if the L1 hypervisor retries these operations. The problem does not affect scenarios where the nested VM-Enter is not involved, as vmcs12 pages are only pinned if L2 is active.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel KVM nested virtualization code did not properly release vmcs12 pages when a nested VM-Enter operation failed due to an invalid guest state. Specifically, when KVM synthesizes a nested VM-Exit during emulation of VMLAUNCH or VMRESUME, the code path that handles invalid guest states bypassed the nested_vmx_vmexit() API, which is responsible for releasing vmcs12 pages. This omission caused pinned pages and/or mappings to leak if the L1 hypervisor retried the VM-Enter operation. The issue was fixed by ensuring all vmcs12 pages are put in this failure path. The problem does not occur in non-VM-Enter scenarios because vmcs12 pages are only pinned if L2 is active, guaranteeing a full VM-Exit before retrying.
Potential Impact
The vulnerability could cause resource leaks of pinned memory pages or mappings in the KVM nested virtualization environment when nested VM-Enter fails due to invalid guest state. This may lead to increased memory usage and potential stability or performance degradation on the host running nested virtual machines. There is no indication of direct code execution or privilege escalation from this issue.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to ensure vmcs12 pages are properly released when nested VM-Enter fails due to invalid guest state. Users should update to the fixed kernel version once available. Patch status is not explicitly confirmed in the provided data; therefore, check the official Linux kernel advisories or vendor updates for the exact fixed versions and apply them accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8ff4-44g5-rp4f
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-68081"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a774280bf8831d539b061bd
Added to database: 08/08/2026, 14:51:44 UTC
Last enriched: 08/08/2026, 14:55:31 UTC
Last updated: 08/09/2026, 00:41:16 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.