VulnerabilityUndergoing Analysis
CVE-2026-46082
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 INVLPGA should cause a #UD when EFER.SVME is not set.
MEDIUM 5.5EPSS 0.12%
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 INVLPGA should cause a #UD when EFER.SVME is not set. Add a check to properly inject #UD when EFER.SVME=0. [sean: tag for stable@]
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/3ac9d4241d205f5d0df06358349ca718ebb0fa12Patch
- https://git.kernel.org/stable/c/491139c17f8ad5773303068411f6ac5eed438b51Patch
- https://git.kernel.org/stable/c/643125b66ffc1147c66616b749475ba9efb15971Patch
- https://git.kernel.org/stable/c/c15392ed9e49c1a16b4d3a3ccf1b3bf2318a6c28Patch
- https://git.kernel.org/stable/c/d99df02ff427f461102230f9c5b90a6c64ee8e23Patch
- https://git.kernel.org/stable/c/ebb63390142c6458fc37758e0892759989cc159fPatch
- https://git.kernel.org/stable/c/ee24928ecd85db4b68ed111e91fef36af0ca37b0Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.