CVE-2025-37957

KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception

References

Notes

 carnil> Introduced in ed129ec9057f ("KVM: x86: forcibly leave nested mode on vCPU
 carnil> reset"). Vulnerable versions: 5.15.81 6.0.11 6.1-rc7.

Bugs

Status

Branch Status
upstream released (6.15-rc6) [a2620f8932fa9fdabc3d78ed6efb004ca409019f]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.14-upstream-stable released (6.14.7) [e9b28bc65fd3a56755ba503258024608292b4ab1]
6.12-upstream-stable released (6.12.29) [d362b21fefcef7eda8f1cd78a5925735d2b3287c]
6.6-upstream-stable released (6.6.92) [ec24e62a1dd3540ee696314422040180040c1e4a]
6.1-upstream-stable needed
5.10-upstream-stable N/A "Vulnerable code not present"
sid released (6.12.29-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security needed
5.10-bullseye-security N/A "Vulnerable code not present"