Executive brief
A vulnerability named VMSCAPE affects the Linux kernel on x86 processors, where a virtual machine (guest) can interfere with the branch prediction mechanisms of the host software (hypervisor) like QEMU. This could potentially allow a malicious guest to perform speculative execution attacks against the hypervisor process. While existing protections secure the core kernel, this flaw specifically risks the security of the userspace management software that runs the virtual machines.
Technical details
VMSCAPE is a speculative execution vulnerability resulting from insufficient branch predictor isolation between a KVM guest and a userspace hypervisor (e.g., QEMU). An attacker with control over a guest VM can 'poison' branch predictors to influence speculative execution paths in the hypervisor process upon a VMexit. The vulnerability is addressed by implementing a conditional Indirect Branch Prediction Barrier (IBPB) that flushes branch predictor state after a VMexit and before returning to userspace. The mitigation can be controlled via the 'vmscape' kernel parameter and is reported through sysfs vulnerabilities nodes. Patching involves updates to the x86 entry code and KVM vcpu_enter_guest logic to track and issue the IBPB.
Affected products
- Linux Foundation Linux Kernel x86 architecture with KVM enabled
- Siemens SIMATIC CN 4100 < V5.0
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later
Timeline
- 2025-08-14: other: Initial patch authored
- 2025-09-11: advisory: CVE-2025-40300 published
- 2025-09-11: patched: Patches committed to Linux stable tree
References
- https://git.kernel.org/stable/c/15006289e5c38b2a830e1fba221977a27598176c
- https://git.kernel.org/stable/c/2f4f2f8f860cb4c3336a7435ebe8dcfded0c9c6e
- https://git.kernel.org/stable/c/2f8f173413f1cbf52660d04df92d0069c4306d25
- https://git.kernel.org/stable/c/34e5667041050711a947e260fc9ebebe08bddee5
- https://git.kernel.org/stable/c/459274c77b37ac63b78c928b4b4e748d1f9d05c8
- https://git.kernel.org/stable/c/510603f504796c3535f67f55fb0b124a303b44c8
- https://git.kernel.org/stable/c/893387c18612bb452336a5881da0d015a7e8f4a2