Performance & Virtualization

QEMU cannot initialize KVM acceleration

A guest fails to start with KVM or runs using a slower software accelerator. Check hardware support, /dev/kvm access and the chosen domain type.

On this page
  1. Symptoms & scope
  2. Possible causes
  3. Diagnose safely
  4. Evidence-guided next steps
  5. References & review
  6. Related problems

Symptoms & scope

  • QEMU reports failed to initialize KVM.
  • Guest execution is unexpectedly slow when an explicitly permitted TCG fallback is used.

Relevant environment

QEMU on Linux with KVM, direct invocation or libvirt; nested guests depend on host exposure.

Recognizable messages (synthetic examples)
qemu-system-x86_64: failed to initialize kvm: No such file or directory

Read the errno and host validation; absent device and denied access need different fixes.

qemu-system-x86_64: Could not access KVM kernel module: Permission denied

Check the actual QEMU identity and device policy, not only firmware support.

Possible causes

These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.

  • The KVM device may be absent because module, firmware or nested virtualization support is unavailable.
  • The actual QEMU identity or sandbox may be unable to open /dev/kvm; the caller's permissions alone are insufficient evidence.

Diagnose safely

Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.

Check 1

Read-only libvirt host checks from an already installed tool; full visibility may require authorized administrative read access.

virt-host-validate qemu

Interpret the result: Distinguish virtualization capability, KVM device existence and accessibility results. Warnings for unrelated optional devices do not prove KVM is unavailable.

Check 2

Reads KVM device ownership and mode; no VM is created.

ls -l /dev/kvm

Interpret the result: A missing node differs from a denied open. Compare ownership with the real QEMU service identity, not only your shell.

Check 3

Replace example-vm with the guest name; reads its definition and requires existing libvirt access.

virsh -c qemu:///system dumpxml example-vm

Interpret the result: The domain type kvm requests hardware acceleration; qemu denotes software emulation. Direct QEMU accelerator configuration must be inspected in its launch arguments instead.

Evidence-guided next steps

Restore supported KVM exposure

If host validation identifies missing hardware exposure, enable the platform's documented virtualization setting or correct the host's KVM module configuration. For a nested guest, configure exposure on the real parent hypervisor where supported.

Precautions: Firmware or module changes may require a reboot and can affect existing VMs. Keep the previous boot configuration.

Recovery / rollback: Restore prior firmware/module or parent-hypervisor settings and reboot only through the planned maintenance path.

Did this solution help you?

Share this solution#

Correct QEMU identity access and accelerator choice

If /dev/kvm exists but the QEMU identity is denied, grant access through the intended group or narrow device policy and start a fresh identity context. If KVM is the intended requirement, explicitly select it so unsupported fallback does not hide the failure.

Precautions: Do not make all host devices writable or run QEMU as root to bypass one denial. Changing domain type can require a fully stopped guest.

Recovery / rollback: Restore group/device policy and accelerator or domain-type settings, then restart the guest through its manager.

Did this solution help you?

Share this solution#

References & review

This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.