Skip to content
Severe DoS RCE Vulnerabilities in kvmtool Affect Multiple Ubuntu Releases

Severe DoS RCE Vulnerabilities in kvmtool Affect Multiple Ubuntu Releases

First seen 14 Apr 2026, 00:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 14, 2026 at 23:59 UTC
  • •kvmtool vulnerabilities allow denial of service and arbitrary code execution.
  • •Affected Ubuntu versions include 22.04, 20.04, 18.04, and 16.04 LTS.
  • •Users should update to the latest package versions to mitigate risks.

A critical security flaw has been identified in kvmtool, affecting Ubuntu 22.04 LTS and its derivatives, including 20.04, 18.04, and 16.04 LTS. The vulnerabilities, tracked as CVE-2021-45464 and CVE-2023-2861, allow a malicious guest attacker to exploit memory management issues and improperly handled file systems. These exploits could lead to denial of service or arbitrary code execution on the host system. The vulnerabilities were disclosed on April 13, 2026, and are considered severe due to their potential impact on system integrity and availability. Users are advised to update their systems to the latest package versions to mitigate these risks. Ubuntu Pro users have access to extended security maintenance for these updates. The issues are particularly concerning for environments utilizing kvmtool for virtualization. Immediate action is recommended to prevent exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 179d ago How this analysis works

Timeline

2023-04-15
CVE-2021-45464 published
2023-12-06
CVE-2023-2861 published
2026-04-13
Vulnerabilities disclosed in Ubuntu security notice

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2021-45464 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed