Linux KVM/x86 (tested on 6.1.74): guest-triggered host panic via SMM shadow MMU
A KVM x86 shadow-MMU bug lets an L1 guest panic the Linux host via nested VMX and SMM.
Jinu Kim reported a guest-triggerable host-kernel panic in KVM's x86 shadow MMU, reproduced on Linux 6.1.74 and on pre-fix mainline. An attacker with kernel-level control of an L1 guest can reach it using nested VMX/EPT, Q35 SMM, and two vCPUs. Q35 compatibility SMRAM lets the normal and SMM KVM address spaces access the same backing guest page, and KVM write-tracks a nested-EPT page directory in the normal address space. The report describes a host panic, not confirmed code execution, and cites no CVE or observed exploitation.
- Guest with L1 kernel control can panic the KVM host.
- Reproduced on Linux 6.1.74 and pre-fix mainline.
- Reproducer uses nested VMX/EPT, Q35 SMM, and two vCPUs.
- No CVE or in-the-wild exploitation is cited.
Posted by Jinu Kim on Sep 29 Hello, I found a guest-triggerable host-kernel panic in KVM's x86 shadow MMU. I reproduced it on Linux 6.1.74 and on pre-fix mainline. An attacker with kernel-level control of an L1 guest can reach it; my reproducer uses nested VMX/EPT, Q35 SMM, and two vCPUs. Q35 compatibility SMRAM lets the normal and SMM KVM address spaces access the same backing guest page. KVM write-tracks a nested-EPT page directory in its normal-address-space...
This source does not provide full text. Read it at seclists.org.