Executive brief
QEMU, an open-source machine emulator used to run virtual machines, contains a flaw in its VAPIC (Virtual APIC) feature that allows a privileged guest user to bypass SMRAM (System Management RAM) security protections on Q35/KVM machines. An attacker with root access in a guest operating system can exploit this to inject malicious code into System Management Mode memory, potentially gaining complete control over the host system's security functions.
Technical details
The vulnerability exists in hw/i386/vapic.c, where the VAPIC setup hypercall fails to validate that a writable RAM alias remains within the option ROM window boundary. An attacker with guest root privileges on a Q35/KVM machine can invoke this hypercall to position the alias outside the expected range, causing it to overlap locked SMRAM regions and bypass the chipset D_LCK (SMRAM D-lock) protection mechanism. This out-of-bounds write (CWE-787) allows code injection directly into System Management Mode memory. The attack requires KVM acceleration and privileged guest access; exploitation is not possible on systems with VAPIC disabled or guests using x2APIC/MSR-based TPR access mechanisms. Patches are expected from the QEMU project.
Affected products
- QEMU QEMU <UNKNOWN>
Timeline
- 2026-09-18: disclosed