Junglewise Threat Intelligence

CVE-2025-40038: Linux Kernel KVM SVM denial of service in fastpath emulation

CVE-2025-40038 · Severity: high · CVSS 7.1 · Published 2025-10-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's virtualization component (KVM) for AMD processors could allow a local attacker to cause a system crash. The issue occurs when the system attempts to perform certain fast-track operations while processing virtual machine exits in an environment where specific hardware features are disabled. This results in the system trying to perform a 'sleep' operation in a context where it is strictly forbidden, leading to a kernel panic and denial of service.

Technical details

A bug in the KVM SVM (Secure Virtual Machine) implementation for AMD processors causes a 'sleeping function called from invalid context' error. When KVM is running with 'nrips=false' or the CPU does not provide the next RIP on a VM-Exit, the SVM handler must decode the instruction by reading guest memory. Because fastpath handlers (such as WRMSR and HLT) run with interrupts disabled (atomic context), the potential for a page fault during guest memory access triggers a sleep in an atomic context. This leads to a kernel BUG and system instability. The fix involves skipping these fastpaths when a valid next RIP is not available.

Affected products

  • Linux Linux Kernel 6.5 to 6.17.3

Timeline

  • 2025-08-05: patched: Initial fix commit 0910dd7c9ad45a2605c45fd2bf3d1bcac087687c
  • 2025-10-28: disclosed: CVE-2025-40038 published

References

Related threats