Linux KVM is a hypervisor technology embedded in the Linux kernel that enables hardware virtualization on x86 and other architectures, presenting a critical but narrowly scoped attack surface given its role in virtualizing production workloads and cloud infrastructure. Vulnerabilities affecting this component arise from the complexity of CPU instruction emulation and memory management in the hypervisor layer, where flaws in guest-isolation mechanisms can have broad blast radius across hosted virtual machines. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linux Kvm over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31022MEDIUM NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service. | Nov 2, 2023 | 5.5 | 18 | NO | NO |
CVE-2023-31026MEDIUM NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service. | Nov 2, 2023 | 5.5 | 17 | NO | NO |
CVE-2023-31021MEDIUM NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a malicious user in the guest VM can cause a NULL-pointer derefe | Nov 2, 2023 | 5.5 | 17 | NO | NO |
CVE-2023-31018MEDIUM NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead t | Nov 2, 2023 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linux Kvm.
Media articles that mention a CVE ID that affects a product developed by Linux Kvm — matched by CVE ID, not by vendor name.