With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | - | 5.8 |
| fedoraproject / fedora | 34 | 34.x |
| fedoraproject / fedora | 35 | 35.x |
| fedoraproject / fedora | 36 | 36.x |
| redhat / enterprise_linux | 9.0 | 9.0.x |
| debian / debian_linux | 11.0 | 11.0.x |