Back

HIGH

KVM: x86: smm: number of GPRs in the SMRAM image depends on the image format

Published May 1, 2025

Description

On 64 bit host, if the guest doesn't have X86_FEATURE_LM, KVM will access 16 gprs to 32-bit smram image, causing out-ouf-bound ram access.

On 32 bit host, the rsm_load_state_64/enter_smm_save_state_64 is compiled out, thus access overflow can't happen.

Affected products

Remediation

Red Hat statement

A memory corruption vulnerability exists in the KVM x86 implementation, where the wrong number of General Purpose Registers (GPRs) is accessed in the System Management Mode (SMM) save/restore logic depending on guest architecture. On 64-bit hosts running 32-bit guests without the X86_FEATURE_LM feature, KVM may access out-of-bounds memory when reading or writing the SMRAM image, due to assuming a 64-bit GPR layout. This issue can only be triggered by a local, privileged guest user with access to SMM context or control over crafted guest state in a virtualized environment.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published May 1, 2025
Updated Aug 5, 2026
Reserved May 1, 2025
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date May 1, 2025
ENISA EUVD
Assigner Linux
Published May 1, 2025
Updated Aug 5, 2026
Exploited since n/a
EUVD-2025-12899