In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Ensure liveliness of nested VM-Enter fail tracepoint message
Use the __string() machinery provided by the tracing subystem to make a
copy of the string literals consumed by the "nested VM-Enter failed"
tracepoint. A complete copy is necessary to ensure that the tracepoint
can't outlive the data/memory it consumes and deference stale memory.
Because the tracepoint itself is defined by kvm, if kvm-intel and/or
kvm-amd are built as modules, the memory holding the string literals
defined by the vendor modules will be freed when the module is unloaded,
whereas the tracepoint and its data in the ring buffer will live until
kvm is unloaded (or "indefinitely" if kvm is built-in).
This bug has existed since the tracepoint was added, but was recently
exposed by a new check in tracing to detect exactly this type of bug.
fmt: '%s%s
' current_buffer: ' vmx_dirty_log_t-140127 [003] .... kvm_nested_vmenter_failed: '
WARNING: CPU: 3 PID: 140134 at kernel/trace/trace.c:3759 trace_check_vprintf+0x3be/0x3e0
CPU: 3 PID: 140134 Comm: less Not tainted 5.13.0-rc1-ce2e73ce600a-req #184
Hardware name: ASUS Q87M-E/Q87M-E, BIOS 1102 03/03/2014
RIP: 0010:trace_check_vprintf+0x3be/0x3e0
Code: <0f> 0b 44 8b 4c 24 1c e9 a9 fe ff ff c6 44 02 ff 00 49 8b 97 b0 20
RSP: 0018:ffffa895cc37bcb0 EFLAGS: 00010282
RAX: 0000000000000000 RBX: ffffa895cc37bd08 RCX: 0000000000000027
RDX: 0000000000000027 RSI: 00000000ffffdfff RDI: ffff9766cfad74f8
RBP: ffffffffc0a041d4 R08: ffff9766cfad74f0 R09: ffffa895cc37bad8
R10: 0000000000000001 R11: 0000000000000001 R12: ffffffffc0a041d4
R13: ffffffffc0f4dba8 R14: 0000000000000000 R15: ffff976409f2c000
FS: 00007f92fa200740(0000) GS:ffff9766cfac0000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000559bd11b0000 CR3: 000000019fbaa002 CR4: 00000000001726e0
Call Trace:
trace_event_printf+0x5e/0x80
trace_raw_output_kvm_nested_vmenter_failed+0x3a/0x60 [kvm]
print_trace_line+0x1dd/0x4e0
s_show+0x45/0x150
seq_read_iter+0x2d5/0x4c0
seq_read+0x106/0x150
vfs_read+0x98/0x180
ksys_read+0x5f/0xe0
do_syscall_64+0x40/0xb0
entry_SYSCALL_64_after_hwframe+0x44/0xae
Security readout for executives and security teams
Plain-English summary
This Linux kernel KVM issue can let stale tracepoint data survive after KVM vendor modules unload. On affected virtualization hosts, a local low-privileged user could cause sensitive memory disclosure or host instability. It is important for hypervisors, but the supplied sources do not show active exploitation.
Executive priority
Patch in the normal high-priority kernel maintenance cycle, faster for shared virtualization hosts or systems with untrusted local users. No source indicates emergency internet-scale exploitation, but confidentiality and availability impact are high.
Technical view
The bug is in KVM x86 nested VM-Enter failure tracing. The tracepoint kept pointers to string literals from kvm-intel or kvm-amd modules; after module unload, ring-buffer trace data could dereference freed memory. The fix copies strings using tracing __string() machinery.
Likely exposure
Exposure is most likely on Linux systems running affected 5.4, 5.10, 5.12, or 5.13 kernel lines with KVM x86 enabled, especially hosts using kvm-intel or kvm-amd as modules and nested virtualization tracing paths.
Exploitation context
The CVSS vector is local, low complexity, low privilege, no user interaction. The source bundle marks KEV false and provides no evidence of public exploitation. Treat it as a host-local virtualization risk, not a remotely exploitable internet service issue.
Researcher notes
The root issue is tracepoint lifetime mismatch: KVM-owned tracepoint data may outlive module-owned string storage. Focus validation on affected kernel lineage, KVM module build mode, and whether vendor patches map to the four referenced stable commits.
Mitigation direction
Apply Linux kernel updates containing the referenced stable KVM fixes.
Prioritize virtualization hosts, CI runners, and systems offering local shell access.
Check distribution advisories for backported fixes matching your kernel build.
Avoid unnecessary KVM vendor module unloads before patching, where operationally feasible.
Validation and detection
Inventory Linux kernel versions on KVM-capable x86 hosts.
Confirm whether kvm-intel or kvm-amd are loaded as modules.
Verify installed kernel packages include the referenced stable commits or vendor backports.
Review kernel logs for trace_check_vprintf or kvm_nested_vmenter_failed warnings.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2021-47262 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.