CVE for illumos and distros: VMM/BHYVE
illumos disclosed CVE-2026-102916, a bhyve REP-prefix emulation bug that mishandles CPU flags.
illumos security reported CVE-2026-102916, internal bug 18491, in the bhyve virtual machine monitor. REP-prefix instruction emulation mishandles CPU flags. Emily Albini of Oxide Computer discovered the flaw, and iximeow of Oxide Computer fixed it. The notice does not describe exploitation in the wild.
- CVE-2026-102916 (illumos 18491) is in bhyve VMM instruction emulation.
- REP-prefix emulation mishandles CPU flags.
- Emily Albini of Oxide Computer found it; iximeow fixed it.
- No in-the-wild exploitation is described.
Vulnerabilities mentionedAll →
- CVE-2026-1029166.8—Guest-triggered host panic in illumos bhyve emulatorpublished · illumos-gate (bhyve / vmm instruction emulator)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-102916 | Guest-triggered host panic in illumos bhyve emulator A reachable assertion in the illumos bhyve instruction emulator lets a guest panic the host. When the kernel emulates a REP-prefixed MOVS or STOS that touches guest MMIO, vie_emulate_movs() and vie_emulate_stos() leave the VIES_REPEAT flag set on the last iteration; for kernel-emulated regions (local APIC, I/O APIC, and HPET) that stale flag fails a VERIFY check in vie_advance_pc(). A privileged user inside a guest can aim REP MOVS or REP STOS at the local APIC page and cause a denial of service of the host and every other guest on it. The bug has been present since illumos-gate commit e0c0d44e in 2020 and affects any illumos distribution older than commit 696ecf8d. It is not in CISA KEV, and no public proof-of-concept is known. |
Posted by Dan McDonald on Oct 09 Per https://illumos.topicbox.com/groups/developer/T697a32b688807e56-Mf889eb5783e975446573b373/cve-2026-102916-18491-bhyve-rep-prefix-instr-emulation-fumbles-flags illumos would like to report the following CVE: CVE-2026-102916 18491 bhyve: rep prefix instr emulation fumbles flags This was discovered by Emily Albini, and fixed by iximeow, both of Oxide Computer. Thank you, Dan McDonald, on behalf of illumos security
This source does not provide full text. Read it at seclists.org.