{"id":"CVE-2026-43133","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation\n\nCommit cc3ed80ae69f (\"KVM: nSVM: always use vmcb01 to for vmsave/vmload\nof guest state\") made KVM always use vm…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation\n\nCommit cc3ed80ae69f (\"KVM: nSVM: always use vmcb01 to for vmsave/vmload\nof guest state\") made KVM always use vm…","severity":"high","cvss":7.9,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H","cwe":["CWE-628"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 5.13, < 5.15.202","linux_kernel >= 5.16, < 6.1.165","linux_kernel >= 6.2, < 6.6.128","linux_kernel >= 6.7, < 6.12.75","linux_kernel >= 6.13, < 6.18.16","linux_kernel >= 6.19, < 6.19.6"],"patched":["linux_kernel 6.19.6"],"published":"2026-05-06","updated":"2026-09-15","sourceUpdated":"2026-09-15T12:17:48.040","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-43133","references":[{"url":"https://git.kernel.org/stable/c/0004ecb798b30e90d7ebfe74efae2d9423315a64","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/10063e1251c1485034a018236080792ad083dcc5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/127ccae2c185f62e6ecb4bf24f9cb307e9b9c619","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3880e331b0b31d0d5d3702b124f6c93539cd478a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3b7015000988ba35ecd5648f4b2283960f00543","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d464cf1ed900d47c85393d40b00017b6adfc2e6c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fce2fd4a2ca05670a91015aacccf96a1c26268fd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://access.redhat.com/errata/RHSA-2026:65334","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:66180","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:66357","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:67468","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:67469","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-43133","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2467065","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43133.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-43133"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43133"},{"url":"https://lore.kernel.org/linux-cve-announce/2026050622-CVE-2026-43133-ffea@gregkh/T"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00133,"epssPercentile":0.03178,"ingestedAt":"2026-08-26T16:46:31.728Z","slug":"CVE-2026-43133","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation\n\nCommit cc3ed80ae69f (\"KVM: nSVM: always use vmcb01 to for vmsave/vmload\nof guest state\") made KVM always use vmcb01 for the fields controlled by\nVMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code\nto always use vmcb01.\n\nAs a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not\nintercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01\ninstead of the current VMCB.\n\n## Affected\n\n- `linux_kernel >= 5.13, < 5.15.202`\n- `linux_kernel >= 5.16, < 6.1.165`\n- `linux_kernel >= 6.2, < 6.6.128`\n- `linux_kernel >= 6.7, < 6.12.75`\n- `linux_kernel >= 6.13, < 6.18.16`\n- `linux_kernel >= 6.19, < 6.19.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.19.6`\n\n## Vendor advisories\n\n- **RHSA-2026:65334** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10), Red Hat Enterprise Linux Real Time for NFV (v. 10), Red Hat Enterprise Linux Real Time (v. 10) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65334)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 9 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43133.json)\n- **RHSA-2026:66180** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9), Red Hat Enterprise Linux Real Time for NFV (v. 9), Red Hat Enterprise Linux Real Time (v. 9) · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66180)\n- **RHSA-2026:66357** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:66357)\n- **RHSA-2026:67468** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67468)\n- **RHSA-2026:67469** · Red Hat · fixed in: Red Hat Enterprise Linux NFV (v. 8), Red Hat Enterprise Linux RT (v. 8) · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67469)","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":43.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}