Posted by Jinu Kim on Sep 29 Hello, I found a guest-triggerable host-kernel panic in KVM's x86 shadow MMU. I reproduced it on Linux 6.1.74 and on pre-fix mainline. An attacker with kernel-level control of an L1 guest can reach it; my reproducer uses nested VMX/EPT, Q35 SMM, and two vCPUs.
Linux KVM/x86 (tested on 6.1.74): guest-triggered host panic via SMM shadow MMU
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/978
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.



