---
cve: "CVE-2026-43133"
severity: "HIGH"
cvss: 7.9
epss: "13%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-05-06 12:16:30"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-09T11:31:38+02:00"
---

# CVE-2026-43133

> 7.9 HIGH

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation

Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload
of guest state") made KVM always use vmcb01 for the fields controlled by
VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code
to always use vmcb01.

As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not
intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01
instead of the current VMCB.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 5.15.202
- Kernel ≥ 6.1.165
- Kernel ≥ 6.6.128
- Kernel ≥ 6.12.75
- Kernel ≥ 6.18.16
- Kernel ≥ 6.19.6

## Referenzen

- <https://git.kernel.org/stable/c/10063e1251c1485034a018236080792ad083dcc5>
- <https://git.kernel.org/stable/c/c3b7015000988ba35ecd5648f4b2283960f00543>
- <https://git.kernel.org/stable/c/3880e331b0b31d0d5d3702b124f6c93539cd478a>
- <https://git.kernel.org/stable/c/fce2fd4a2ca05670a91015aacccf96a1c26268fd>
- <https://git.kernel.org/stable/c/d464cf1ed900d47c85393d40b00017b6adfc2e6c>
- <https://git.kernel.org/stable/c/0004ecb798b30e90d7ebfe74efae2d9423315a64>
- <https://git.kernel.org/stable/c/127ccae2c185f62e6ecb4bf24f9cb307e9b9c619>
- <https://access.redhat.com/security/cve/CVE-2026-43133>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2467065>
- <https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43133.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-43133) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
