Executive brief
A vulnerability in the Linux kernel's virtualization component (KVM) for AMD processors could allow a local attacker to cause a system crash. The issue occurs when the system attempts to perform certain fast-track operations while processing virtual machine exits in an environment where specific hardware features are disabled. This results in the system trying to perform a 'sleep' operation in a context where it is strictly forbidden, leading to a kernel panic and denial of service.
Technical details
A bug in the KVM SVM (Secure Virtual Machine) implementation for AMD processors causes a 'sleeping function called from invalid context' error. When KVM is running with 'nrips=false' or the CPU does not provide the next RIP on a VM-Exit, the SVM handler must decode the instruction by reading guest memory. Because fastpath handlers (such as WRMSR and HLT) run with interrupts disabled (atomic context), the potential for a page fault during guest memory access triggers a sleep in an atomic context. This leads to a kernel BUG and system instability. The fix involves skipping these fastpaths when a valid next RIP is not available.
Affected products
- Linux Linux Kernel 6.5 to 6.17.3
Timeline
- 2025-08-05: patched: Initial fix commit 0910dd7c9ad45a2605c45fd2bf3d1bcac087687c
- 2025-10-28: disclosed: CVE-2025-40038 published