[PATCH 1/3] KVM: nVMX: Clear stale vmcs02 sync flag in free_nested()

From: Mushahid Hussain

Date: Mon Oct 05 2026 - 15:25:28 EST


free_nested() frees vmcs02 but leaves need_sync_vmcs02_to_vmcs12_rare
set. The flag means that the rare guest fields of vmcs12 are valid
only in vmcs02. After vmcs02 is freed the flag is wrong.

L1 then executes VMXON and loads a vmcs12 with VMPTRLD. The flag is
still set, so the first sync copies the rare fields from the new,
never launched vmcs02 into vmcs12. This sets TR, LDTR, GDTR, IDTR,
the segment registers and the FS/GS bases to zero in guest memory.
set_current_vmptr() re-arms the other lazy flags at VMPTRLD. This
flag has no such point, so VMXOFF is the place to clear it.

A nested Hyper-V follows this sequence when it resumes from
hibernation. It executes VMXOFF before hibernation. On resume, it
reloads the VMCS images that winresume restored from the hiberfile.
VM-entry fails with exit reason 0x80000021 (invalid guest state) and
the guest hypervisor resets the machine. vmx_leave_nested() also goes
through free_nested(), so KVM_SET_NESTED_STATE takes the same path.

Clear the flag together with the other nested state.

Fixes: 7952d769c29c ("KVM: nVMX: Sync rarely accessed guest fields only when needed")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: Claude:claude-fable-5.1
Signed-off-by: Mushahid Hussain <hmushi@xxxxxxxxxxxx>
---
arch/x86/kvm/vmx/nested.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c
index 9b0bfa2f854cf..6c3723ddd40b8 100644
--- a/arch/x86/kvm/vmx/nested.c
+++ b/arch/x86/kvm/vmx/nested.c
@@ -350,6 +350,7 @@ static void free_nested(struct kvm_vcpu *vcpu)
vmx->nested.vmxon = false;
vmx->nested.smm.vmxon = false;
vmx->nested.vmxon_ptr = INVALID_GPA;
+ vmx->nested.need_sync_vmcs02_to_vmcs12_rare = false;
free_vpid(vmx->nested.vpid02);
vmx->nested.posted_intr_nv = -1;
vmx->nested.current_vmptr = INVALID_GPA;
--
2.47.3