Answer in brief
CVE-2024-50115 records a Unknown severity vulnerability in KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-50115 records a Unknown severity vulnerability in KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <76ce386feb14ec9a460784fcd495d8432acce7a5 || >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <58cb697d80e669c56197f703e188867c8c54c494 || >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <6876793907cbe19d42e9edc8c3315a21e06c32ae || >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <2c4adc9b192a0815fe58a62bc0709449416cc884 || >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <426682afec71ea3f889b972d038238807b9443e4 || >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <f559b2e9c5c5308850544ab59396b7d53cfc67bd | 76ce386feb14ec9a460784fcd495d8432acce7a5, 58cb697d80e669c56197f703e188867c8c54c494, 6876793907cbe19d42e9edc8c3315a21e06c32ae, 2c4adc9b192a0815fe58a62bc0709449416cc884, 426682afec71ea3f889b972d038238807b9443e4, f559b2e9c5c5308850544ab59396b7d53cfc67bd |
| Linux/Linuxgeneric | 3.2 | Not reported |
Published upstream
Nov 5, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory Ignore nCR3[4:0] when loading PDPTEs from memory for nested SVM, as bits 4:0 of CR3 are ignored when PAE paging is used, and thus VMRUN doesn't enforce 32-byte alignment of nCR3. In the absolute worst case scenario, failure to ignore bits 4:0 can result in an out-of-bounds read, e.g. if the target page is at the end of a memslot, and the VMM isn't using guard pages. Per the APM: The CR3 register points to the base address of the page-directory-pointer table. The page-directory-pointer table is aligned on a 32-byte boundary, with the low 5 address bits 4:0 assumed to be 0. And the SDM's much more explicit: 4:0 Ignored Note, KVM gets this right when loading PDPTRs, it's only the nSVM flow that is broken.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <76ce386feb14ec9a460784fcd495d8432acce7a5 || >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <58cb697d80e669c56197f703e188867c8c54c494 || >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <6876793907cbe19d42e9edc8c3315a21e06c32ae || >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <2c4adc9b192a0815fe58a62bc0709449416cc884 || >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <426682afec71ea3f889b972d038238807b9443e4 || >=e4e517b4be019787ada4cbbce2f04570c21b0cbd <f559b2e9c5c5308850544ab59396b7d53cfc67bd | 76ce386feb14ec9a460784fcd495d8432acce7a5, 58cb697d80e669c56197f703e188867c8c54c494, 6876793907cbe19d42e9edc8c3315a21e06c32ae, 2c4adc9b192a0815fe58a62bc0709449416cc884, 426682afec71ea3f889b972d038238807b9443e4, f559b2e9c5c5308850544ab59396b7d53cfc67bd |
| Linux/Linuxgeneric | 3.2 | Not reported |
Published upstream
Nov 5, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory Ignore nCR3[4:0] when loading PDPTEs from memory for nested SVM, as bits 4:0 of CR3 are ignored when PAE paging is used, and thus VMRUN doesn't enforce 32-byte alignment of nCR3. In the absolute worst case scenario, failure to ignore bits 4:0 can result in an out-of-bounds read, e.g. if the target page is at the end of a memslot, and the VMM isn't using guard pages. Per the APM: The CR3 register points to the base address of the page-directory-pointer table. The page-directory-pointer table is aligned on a 32-byte boundary, with the low 5 address bits 4:0 assumed to be 0. And the SDM's much more explicit: 4:0 Ignored Note, KVM gets this right when loading PDPTRs, it's only the nSVM flow that is broken.
Quoted source text, attributed separately from HOL analysis.