CVE-2025-37957 Information
Description
In the Linux kernel the following vulnerability has been resolved:
KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception
Previously commit ed129ec9057f (\KVM: x86: forcibly leave nested mode on vCPU reset) addressed an issue where a triple fault occurring in nested mode could lead to use-after-free scenarios. However the commit did not handle the analogous situation for System Management Mode (SMM).
This omission results in triggering a WARN when KVM forces a vCPU INIT after SHUTDOWN interception while the vCPU is in SMM. This situation was reprodused using Syzkaller by:
- Creating a KVM VM and vCPU
- Sending a KVM_SMI ioctl to explicitly enter SMM
- Executing invalid instructions causing consecutive exceptions and eventually a triple fault
The issue manifests as follows:
WARNING: CPU: 0 PID: 25506 at arch/x86/kvm/x86.c:12112
kvm_vcpu_reset+0x1d2/0x1530 arch/x86/kvm/x86.c:12112
Modules linked in:
CPU: 0 PID: 25506 Comm: syz-executor.0 Not tainted
6.1.130-syzkaller-00157-g164fe5dde9b6 0
Hardware name: QEMU Standard PC (i440FX + PIIX 1996)
BIOS 1.12.0-1 04/01/2014
RIP: 0010:kvm_vcpu_reset+0x1d2/0x1530 arch/x86/kvm/x86.c:12112
Call Trace:
Architecturally INIT is blocked when the CPU is in SMM hence KVM’s WARN() in kvm_vcpu_reset() to guard against KVM bugs e.g. to detect improper emulation of INIT. SHUTDOWN on SVM is a weird edge case where KVM needs to do something sane with the VMCB since it’s technically undefined and INIT is the least awful choice given KVM’s ABI.
So double down on stuffing INIT on SHUTDOWN and force the vCPU out of SMM to avoid any weirdness (and the WARN).
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
[sean: massage changelog make it clear this isn’t architectural behavior]
Reference
https://git.kernel.org/stable/c/a2620f8932fa9fdabc3d78ed6efb004ca409019f https://git.kernel.org/stable/c/d362b21fefcef7eda8f1cd78a5925735d2b3287c https://git.kernel.org/stable/c/e9b28bc65fd3a56755ba503258024608292b4ab1
Share on: