Executive brief
A vulnerability in the Linux kernel's virtualization component (KVM) could allow a user on a guest virtual machine to access sensitive information from the host system. By exploiting how the system handles specific processor instructions, an attacker could bypass security boundaries to read data they should not have access to. This issue primarily affects environments running virtualized workloads on x86 hardware.
Technical details
A speculative execution side-channel vulnerability exists in the Linux kernel's KVM x86 implementation. The functions __pv_send_ipi and kvm_sched_yield use guest-controlled indices (min and dest_id) to access the phys_map array. While bounds checks were present, they did not account for speculative execution, potentially allowing an attacker to leak host memory via a Spectre-style side-channel. The fix introduces array_index_nospec() to clamp these indices after bounds checking, ensuring that speculative execution cannot access out-of-bounds memory. This affects various stable kernel branches from 4.19 through 6.16.
Affected products
- Linux Linux Kernel 4.19 to 5.4.298, 5.5 to 5.10.242, 5.11 to 5.15.191, 5.16 to 6.1.150, 6.2 to 6.6.104, 6.7 to 6.12.45, 6.13 to 6.16.5
Timeline
- 2025-08-04: other: Patch authored
- 2025-09-16: disclosed: NVD Published Date
- 2025-09-16: patched: Kernel stable updates released
References
- https://git.kernel.org/stable/c/31a0ad2f60cb4816e06218b63e695eb72ce74974
- https://git.kernel.org/stable/c/33e974c2d5a82b2f9d9ba0ad9cbaabc1c8e3985f
- https://git.kernel.org/stable/c/67a05679621b7f721bdba37a5d18665d3aceb695
- https://git.kernel.org/stable/c/72777fc31aa7ab2ce00f44bfa3929c6eabbeaf48
- https://git.kernel.org/stable/c/c87bd4dd43a624109c3cc42d843138378a7f4548
- https://git.kernel.org/stable/c/d51e381beed5e2f50f85f49f6c90e023754efa12
- https://git.kernel.org/stable/c/f49161646e03d107ce81a99c6ca5da682fe5fb69