Executive brief
A vulnerability was identified in the Linux kernel's virtualization component (KVM) on x86 systems. KVM is responsible for managing virtual machines and their interactions with hardware. This flaw could allow a user within a virtual machine to trigger a system crash or instability by manipulating how the system handles input/output operations, potentially leading to a denial of service for the host server.
Technical details
A vulnerability in the Linux kernel's KVM x86 implementation arises when completing emulation of instructions that generated a userspace exit for I/O. KVM incorrectly re-checks L1 intercepts during this phase. If the I/O permission bitmaps are modified by L1 or host userspace during the exit, KVM may treat the access as intercepted even though emulation was already committed. This logic error can be triggered by a local attacker using a crafted program to toggle port I/O interception, resulting in a non-zero 'vcpu->arch.pio.count' and a kernel WARN/instability. The fix involves pivoting on EMULTYPE_NO_DECODE to skip redundant intercept checks during I/O completion.
Affected products
- Linux Linux Kernel 8a76d7f25f8f to e750f8539128
Timeline
- 2025-07-15: patched: Initial fix committed to mainline kernel
- 2025-10-28: disclosed: CVE-2025-40026 published
References
- https://git.kernel.org/stable/c/00338255bb1f422642fb2798ebe92e93b6e4209b
- https://git.kernel.org/stable/c/3a062a5c55adc5507600b9ae6d911e247e2f1d6e
- https://git.kernel.org/stable/c/3d3abf3f7e8b1abb082070a343de82d7efc80523
- https://git.kernel.org/stable/c/7366830642505683bbe905a2ba5d18d6e4b512b8
- https://git.kernel.org/stable/c/a908eca437789589dd4624da428614c1275064dc
- https://git.kernel.org/stable/c/ba35a5d775799ce5ad60230be97336f2fefd518e
- https://git.kernel.org/stable/c/e0ce3ed1048a47986d15aef1a98ebda25560d257