PT-2025-22218 · Linux+5 · Linux Kernel+5
Published
2025-04-14
·
Updated
2026-04-20
·
CVE-2025-37957
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to the fixed version
Description
A vulnerability in the Linux kernel has been resolved, related to KVM (Kernel-based Virtual Machine) and SVM (Secure Virtual Machine). The issue occurs when a triple fault happens in System Management Mode (SMM), leading to a use-after-free scenario. This situation can trigger a WARN when KVM forces a vCPU INIT after SHUTDOWN interception while the vCPU is in SMM. The issue was reproduced using Syzkaller by creating a KVM VM and vCPU, sending a KVM SMI ioctl to enter SMM, and executing invalid instructions causing consecutive exceptions and a triple fault.
Recommendations
For Linux kernel versions prior to the fixed version, consider updating to a newer version that includes the fix for this issue. As a temporary workaround, consider disabling the
kvm vcpu reset() function until a patch is available. Restrict access to the vulnerable svm invoke exit handler() function to minimize the risk of exploitation. Avoid using the KVM SMI ioctl in the affected API endpoint until the issue is resolved.Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu