PT-2025-37194 · Linux+9 · Linux Kernel+9

Published

2025-08-14

·

Updated

2026-05-26

·

CVE-2025-40300

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description VMScape is a vulnerability that exploits insufficient branch predictor isolation between a guest and a userspace hypervisor (like QEMU). The vulnerability allows a malicious virtual machine to extract cryptographic keys from a non-modified QEMU process running on modern AMD or Intel processors. It bypasses existing Spectre mitigations and threatens confidential data leakage by exploiting speculative execution. The attack targets QEMU, a user-mode hypervisor component, utilizing a FLUSH+RELOAD cache timing channel. It leverages Spectre-BTI (Branch Target Injection) to mislead indirect branch predictions in QEMU, causing speculative execution of a data-leaking gadget. The vulnerability impacts all AMD Zen processors (Zen 1 through Zen 5) and Intel Coffee Lake processors. Newer processors, Raptor Cove and Gracemont, are not affected. The attack can potentially lead to data leakage between VMs of different clients, hypervisor compromise from a guest VM, and theft of cryptographic keys, violating isolation in multi-tenant environments.
Recommendations Update the Linux kernel to a version that includes the conditional IBPB mitigation, which flushes the branch predictor unit (BPU) when switching from guest to host.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALSA-2025:19930
ALSA-2025:19931
ALSA-2025:19932
AZL-67238
AZL-74763
BDU:2025-15665
CESA-2025_19931
CESA-2025_19932
CVE-2025-40300
DLA-4327-1
DLA-4328-1
DSA-6008-1
DSA-6009-1
ECHO-C760-4922-7C11
INFESA-2025_0006
INFSA-2025_19931
INFSA-2025_19932
INFSA-2025_21112
MGASA-2025-0309
MGASA-2025-0310
OESA-2026-1337
OESA-2026-1338
OESA-2026-1339
OPENSUSE-SU-2025:15553-1
OPENSUSE-SU-2025:20081-1
OPENSUSE-SU-2026:10301-1
RHSA-2025:19930
RHSA-2025:19931
RHSA-2025:19932
RHSA-2025:21112
RHSA-2025:21118
RHSA-2025_19930
RHSA-2025_19931
RHSA-2025_19932
RHSA-2025_21112
RHSA-2026:0271
SUSE-SU-2025:03600-1
SUSE-SU-2025:03601-1
SUSE-SU-2025:03614-1
SUSE-SU-2025:03633-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3725-1
SUSE-SU-2025:3751-1
SUSE-SU-2026:0411-1
SUSE-SU-2026:0474-1
SUSE-SU-2026:0496-1
SUSE-SU-2026:0617-1
USN-7850-1
USN-7853-1
USN-7853-2
USN-7853-3
USN-7854-1
USN-7860-1
USN-7860-2
USN-7860-3
USN-7860-4
USN-7860-5
USN-7861-1
USN-7861-2
USN-7861-3
USN-7861-4
USN-7861-5
USN-7862-1
USN-7862-2
USN-7862-3
USN-7863-1
USN-7864-1
USN-7865-1
USN-7874-1
USN-7874-2
USN-7874-3
USN-7875-1
USN-7910-1
USN-7910-2
USN-7933-1
USN-7934-1
USN-7935-1
USN-7937-1
USN-7938-1
USN-7939-1
USN-7939-2
USN-7940-1
USN-7940-2

Affected Products

Almalinux
Centos
Debian
Linuxmint
Linux Kernel
Qemu
Red Hat
Rocky Linux
Suse
Ubuntu