{"id":"DEBIAN-CVE-2023-53756","details":"In the Linux kernel, the following vulnerability has been resolved:  KVM: VMX: Fix crash due to uninitialized current_vmcs  KVM enables 'Enlightened VMCS' and 'Enlightened MSR Bitmap' when running as a nested hypervisor on top of Hyper-V. When MSR bitmap is updated, evmcs_touch_msr_bitmap function uses current_vmcs per-cpu variable to mark that the msr bitmap was changed.  vmx_vcpu_create() modifies the msr bitmap via vmx_disable_intercept_for_msr -\u003e vmx_msr_bitmap_l01_changed which in the end calls this function. The function checks for current_vmcs if it is null but the check is insufficient because current_vmcs is not initialized. Because of this, the code might incorrectly write to the structure pointed by current_vmcs value left by another task. Preemption is not disabled, the current task can be preempted and moved to another CPU while current_vmcs is accessed multiple times from evmcs_touch_msr_bitmap() which leads to crash.  The manipulation of MSR bitmaps by callers happens only for vmcs01 so the solution is to use vmx-\u003evmcs01.vmcs instead of current_vmcs.    BUG: kernel NULL pointer dereference, address: 0000000000000338   PGD 4e1775067 P4D 0   Oops: 0002 [#1] PREEMPT SMP NOPTI   ...   RIP: 0010:vmx_msr_bitmap_l01_changed+0x39/0x50 [kvm_intel]   ...   Call Trace:    vmx_disable_intercept_for_msr+0x36/0x260 [kvm_intel]    vmx_vcpu_create+0xe6/0x540 [kvm_intel]    kvm_arch_vcpu_create+0x1d1/0x2e0 [kvm]    kvm_vm_ioctl_create_vcpu+0x178/0x430 [kvm]    kvm_vm_ioctl+0x53f/0x790 [kvm]    __x64_sys_ioctl+0x8a/0xc0    do_syscall_64+0x5c/0x90    entry_SYSCALL_64_after_hwframe+0x63/0xcd","modified":"2026-09-15T08:47:34.832527525Z","published":"2025-12-08T02:15:51.243Z","upstream":["CVE-2023-53756"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53756"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53756.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53756.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53756.json"}}],"schema_version":"1.9.0"}