# CVE-2026-43133

## Summary

- **CVE ID:** CVE-2026-43133
- **Severity:** HIGH
- **CVSS Score:** 7.9 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H)
- **CWE:** N/A
- **Published:** May 6, 2026
- **Last Modified:** Sep 15, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation

Commit cc3ed80ae69f ("KVM: nSVM: always use vmcb01 to for vmsave/vmload
of guest state") made KVM always use vmcb01 for the fields controlled by
VMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code
to always use vmcb01.

As a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not
intercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01
instead of the current VMCB.

## Affected Products

- Linux — Linux (cc3ed80ae69f454c3d904af9f65394a540099723)
- Linux — Linux (5.13)
- Linux — Linux (0)
- Linux — Linux (5.15.202)
- Linux — Linux (6.1.165)
- Linux — Linux (6.6.128)
- Linux — Linux (6.12.75)
- Linux — Linux (6.18.16)
- Linux — Linux (6.19.6)
- Linux — Linux (7.0)

## References

- [CNA](https://git.kernel.org/stable/c/10063e1251c1485034a018236080792ad083dcc5)
- [CNA](https://git.kernel.org/stable/c/c3b7015000988ba35ecd5648f4b2283960f00543)
- [CNA](https://git.kernel.org/stable/c/3880e331b0b31d0d5d3702b124f6c93539cd478a)
- [CNA](https://git.kernel.org/stable/c/fce2fd4a2ca05670a91015aacccf96a1c26268fd)
- [CNA](https://git.kernel.org/stable/c/d464cf1ed900d47c85393d40b00017b6adfc2e6c)
- [CNA](https://git.kernel.org/stable/c/0004ecb798b30e90d7ebfe74efae2d9423315a64)
- [CNA](https://git.kernel.org/stable/c/127ccae2c185f62e6ecb4bf24f9cb307e9b9c619)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2026-43133)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2467065)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43133.json)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:65334)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:66180)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:66357)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:67468)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:67469)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 3.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._