关于KVM逃逸漏洞(CVE-2026-53359)的处理建议

尊敬的用户:

近期关注到 KVM 逃逸漏洞 (CVE-2026-53359) 可能带来安全风险。 为降低风险影响,建议您根据节点使用情况按以下方式处理:

一、已在使用中的节点

建议通过关闭嵌套虚拟化来规避该问题。关闭前,请先关闭节点内所有小鸡,避免影响业务运行或导致配置变更失败。 操作完成后,请检查节点状态,并确认配置已生效。

二、仍需使用嵌套虚拟化的节点

关闭嵌套虚拟化仅属于风险缓解措施,不等同于系统已完成漏洞修复。 如业务必须依赖嵌套虚拟化,建议更换或升级至已修复该问题的系统版本,从内核层面解决安全风险。

三、新安装节点

新安装节点将默认关闭嵌套虚拟化。后续版本会在魔方云后台增加嵌套虚拟化的开启/关闭功能,便于您按需管理。

说明:如您确需开启嵌套虚拟化,仍建议优先切换至已修复的系统版本后再启用。

感谢您的理解与支持!

下方是关于漏洞的详细公告CVE漏洞平台披露

Updated: 2026-07-04


Published: 2026-07-04

Title: KVM: x86: Fix shadow paging use-after-free due to unexpected role


Description

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. The rmap_remove() call would miss entries created after the PDE change because the GFN of the leaf SPTE does not match the GFN of the struct kvm_mmu_page. A similar hole however remains if the modified PDE points to a non-leaf page. In this case the gfn can be made to match, but the role does not match: the original large 2MB page creates a kvm_mmu_page with direct=1, while the new 4KB needs a kvm_mmu_page with direct=0. However, kvm_mmu_get_child_sp() does not compare the role, and therefore reuses the page. The next step is installing a leaf (4KB) SPTE on the new path which records an rmap entry under the gfn resolved by the walk. But when that child is zapped its parent kvm_mmu_page has direct=1 and kvm_mmu_page_get_gfn() computes the gfn for the 4KB page as sp->gfn + index instead of using sp->shadowed_translation[] (or sp->gfns[] in older kernels). It therefore fails to remove the recorded entry. When the memslot is dropped the shadow page is freed but the rmap entry survives, as in the scenario that was already fixed. Code that later walks that gfn (dirty logging, MMU notifier invalidation, and so on) dereferences an sptep that lies in the freed page, causing the use-after-free.


Product Status

Learn more

Vendor


Linux


Product


Linux


Versions 6 Total


Default Status: unaffected


Affected


affected from 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 before b1337aae5e194324e4810d561764e7793f8b3864 

affected from 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 before 9291654d69e08542de37755cebe4d5b02c3170d1 

affected from 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 before 2ad3afa40ac6aa340dada122f9abfa46c0a6eb35 

affected from 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 before 5e470998a23e4c3d89ed24e8172cb22747e61efa 

affected from 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 before 1ae7d5a6db6c190ce183e3098ca0e0846e14d462 

affected from 2032a93d66fa282ba0f2ea9152eeff9511fa9a96 before 81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb 

Vendor


Linux


Product


Linux


Versions 8 Total


Default Status: affected


Affected


affected at 2.6.36 

Unaffected


unaffected from 0 before 2.6.36 

unaffected from 6.1.177 through 6.1.* 

unaffected from 6.6.144 through 6.6.* 

unaffected from 6.12.95 through 6.12.* 

unaffected from 6.18.38 through 6.18.* 

unaffected from 7.1.3 through 7.1.* 

unaffected from 7.2-rc1 

References 6 Total

https://git.kernel.org/stable/c/b1337aae5e194324e4810d561764e7793f8b3864

https://git.kernel.org/stable/c/9291654d69e08542de37755cebe4d5b02c3170d1

https://git.kernel.org/stable/c/2ad3afa40ac6aa340dada122f9abfa46c0a6eb35

https://git.kernel.org/stable/c/5e470998a23e4c3d89ed24e8172cb22747e61efa

https://git.kernel.org/stable/c/1ae7d5a6db6c190ce183e3098ca0e0846e14d462

https://git.kernel.org/stable/c/81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb

分享到:
上一篇
芒竹云计算(湖北)有限责任公司关于周国辉同志任职的通知
服务中心
客服
在线客服
24小时为您服务
咨询
联系我们
联系我们,为您的业务提供专属服务。
24/7 技术支持
如果您遇到寻求进一步的帮助,请过工单与我们进行联系。
24/7 即时支持
芒竹智能云
芒竹智能云
售后客服
评价
您对当前页面的整体感受是否满意?
😞
非常不满意
😕
不满意
😐
一般
🙂
满意
😊
非常满意