CVE-2025-23141

EUVD-2025-13106
In the Linux kernel, the following vulnerability has been resolved:

KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses

Acquire a lock on kvm->srcu when userspace is getting MP state to handle a
rather extreme edge case where "accepting" APIC events, i.e. processing
pending INIT or SIPI, can trigger accesses to guest memory.  If the vCPU
is in L2 with INIT *and* a TRIPLE_FAULT request pending, then getting MP
state will trigger a nested VM-Exit by way of ->check_nested_events(), and
emuating the nested VM-Exit can access guest memory.

The splat was originally hit by syzkaller on a Google-internal kernel, and
reproduced on an upstream kernel by hacking the triple_fault_event_test
selftest to stuff a pending INIT, store an MSR on VM-Exit (to generate a
memory access on VMX), and do vcpu_mp_state_get() to trigger the scenario.

  =============================
  WARNING: suspicious RCU usage
  6.14.0-rc3-b112d356288b-vmx/pi_lockdep_false_pos-lock #3 Not tainted
  -----------------------------
  include/linux/kvm_host.h:1058 suspicious rcu_dereference_check() usage!

  other info that might help us debug this:

  rcu_scheduler_active = 2, debug_locks = 1
  1 lock held by triple_fault_ev/1256:
   #0: ffff88810df5a330 (&vcpu->mutex){+.+.}-{4:4}, at: kvm_vcpu_ioctl+0x8b/0x9a0 [kvm]

  stack backtrace:
  CPU: 11 UID: 1000 PID: 1256 Comm: triple_fault_ev Not tainted 6.14.0-rc3-b112d356288b-vmx #3
  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
  Call Trace:
   <TASK>
   dump_stack_lvl+0x7f/0x90
   lockdep_rcu_suspicious+0x144/0x190
   kvm_vcpu_gfn_to_memslot+0x156/0x180 [kvm]
   kvm_vcpu_read_guest+0x3e/0x90 [kvm]
   read_and_check_msr_entry+0x2e/0x180 [kvm_intel]
   __nested_vmx_vmexit+0x550/0xde0 [kvm_intel]
   kvm_check_nested_events+0x1b/0x30 [kvm]
   kvm_apic_accept_events+0x33/0x100 [kvm]
   kvm_arch_vcpu_ioctl_get_mpstate+0x30/0x1d0 [kvm]
   kvm_vcpu_ioctl+0x33e/0x9a0 [kvm]
   __x64_sys_ioctl+0x8b/0xb0
   do_syscall_64+0x6c/0x170
   entry_SYSCALL_64_after_hwframe+0x4b/0x53
   </TASK>
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
𝑥
< 6.1.135
linuxlinux_kernel
6.2 ≤
𝑥
< 6.6.88
linuxlinux_kernel
6.7 ≤
𝑥
< 6.12.24
linuxlinux_kernel
6.13 ≤
𝑥
< 6.13.12
linuxlinux_kernel
6.14 ≤
𝑥
< 6.14.3
linuxlinux_kernel
6.15:rc1
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.170-3
fixed
bookworm (security)
6.1.174-1
fixed
bullseye
5.10.223-1
fixed
bullseye (security)
5.10.257-1
fixed
forky
7.0.10-1
fixed
sid
7.0.10-1
fixed
trixie
6.12.86-1
fixed
trixie (security)
6.12.90-2
fixed
linux-6.1
bullseye (security)
6.1.174-1~deb11u1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cluster-md-kmp-default
suse enterprise server 12 SP5
4.12.14-122.272.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
dlm-kmp-default
suse enterprise server 12 SP5
4.12.14-122.272.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
gfs2-kmp-default
suse enterprise server 12 SP5
4.12.14-122.272.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
kernel-64kb
suse enterprise desktop 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.170.2
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.6.1
fixed
kernel-azure
suse enterprise sap 15 SP6
6.4.0-150600.8.40.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.20.6.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.8.40.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.20.6.1
fixed
kernel-default
suse enterprise desktop 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise server 12 SP5
4.12.14-122.272.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.170.2
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.6.1
fixed
kernel-default-base
suse enterprise desktop 15 SP6
6.4.0-150600.23.53.1.150600.12.24.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.6.1.150700.17.6.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.53.1.150600.12.24.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.6.1.150700.17.6.1
fixed
suse enterprise server 12 SP5
4.12.14-122.272.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.170.2.150400.24.86.2
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1.150500.6.53.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.53.1.150600.12.24.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.6.1.150700.17.6.1
fixed
kernel-default-man
suse enterprise server 12 SP5
4.12.14-122.272.1
fixed
kernel-docs
suse enterprise desktop 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.170.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.6.1
fixed
kernel-macros
suse enterprise desktop 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise server 12 SP5
4.12.14-122.272.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.170.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.6.1
fixed
kernel-obs-build
suse enterprise desktop 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.170.2
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.6.1
fixed
kernel-source
suse enterprise desktop 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise server 12 SP5
4.12.14-122.272.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.170.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.6.1
fixed
kernel-source-azure
suse enterprise sap 15 SP6
6.4.0-150600.8.40.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.20.6.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.8.40.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.20.6.1
fixed
kernel-syms
suse enterprise desktop 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise server 12 SP5
4.12.14-122.272.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.170.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.6.1
fixed
kernel-syms-azure
suse enterprise sap 15 SP6
6.4.0-150600.8.40.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.20.6.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.8.40.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.20.6.1
fixed
kernel-zfcpdump
suse enterprise desktop 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise desktop 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise sap 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.6.1
fixed
suse enterprise server 15 SP4
5.14.21-150400.24.170.2
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
suse enterprise server 15 SP6
6.4.0-150600.23.53.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.6.1
fixed
ocfs2-kmp-default
suse enterprise server 12 SP5
4.12.14-122.272.1
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed
reiserfs-kmp-default
suse enterprise server 15 SP4
5.14.21-150400.24.170.2
fixed
suse enterprise server 15 SP5
5.14.21-150500.55.113.1
fixed