Junglewise Threat Intelligence

CVE-2025-40300: Linux Kernel VMSCAPE branch predictor isolation flaw in x86 KVM

CVE-2025-40300 · Severity: medium · CVSS 5.5 · Published 2025-09-11

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Linux Foundation, Siemens, Linux.

Executive brief

A vulnerability named VMSCAPE affects the Linux kernel on x86 processors, where a virtual machine (guest) can interfere with the branch prediction mechanisms of the host software (hypervisor) like QEMU. This could potentially allow a malicious guest to perform speculative execution attacks against the hypervisor process. While existing protections secure the core kernel, this flaw specifically risks the security of the userspace management software that runs the virtual machines.

Technical details

VMSCAPE is a speculative execution vulnerability resulting from insufficient branch predictor isolation between a KVM guest and a userspace hypervisor (e.g., QEMU). An attacker with control over a guest VM can 'poison' branch predictors to influence speculative execution paths in the hypervisor process upon a VMexit. The vulnerability is addressed by implementing a conditional Indirect Branch Prediction Barrier (IBPB) that flushes branch predictor state after a VMexit and before returning to userspace. The mitigation can be controlled via the 'vmscape' kernel parameter and is reported through sysfs vulnerabilities nodes. Patching involves updates to the x86 entry code and KVM vcpu_enter_guest logic to track and issue the IBPB.

Affected products

  • Linux Foundation Linux Kernel x86 architecture with KVM enabled
  • Siemens SIMATIC CN 4100 < V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later

Timeline

  • 2025-08-14: other: Initial patch authored
  • 2025-09-11: advisory: CVE-2025-40300 published
  • 2025-09-11: patched: Patches committed to Linux stable tree

References

Related threats