天下漏洞,尽知其名
MEDIUM

CVE-2026-102916 illumos bhyve 指令模拟器断言失败漏洞

影响guest 内特权用户可导致宿主机 panic,造成拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

illumos bhyve 指令模拟器在模拟带 REP 前缀的 MOVS/STOS 指令访问 guest MMIO 时,未在最后一次迭代清除 VIES_REPEAT 状态标志。对于内核模拟的 MMIO 区域(本地 APIC、I/O APIC、HPET),残留标志会触发 vie_advance_pc() 中的 VERIFY 断言失败,导致宿主机 panic。该缺陷自 2020 年起存在。

影响范围

illumos bhyve

影响 illumos-gate commit 696ecf8d 之前的所有 illumos 发行版,缺陷自 2020 年 commit e0c0d44e 引入。

漏洞详情

漏洞类型为断言失败导致的拒绝服务。成因是 vie_emulate_movs() 和 vie_emulate_stos() 在处理 REP 前缀指令的最终迭代时未清除 VIES_REPEAT 标志,残留状态使 vie_advance_pc() 的 VERIFY 断言失败。guest 内特权用户可对本地 APIC 页发起 REP MOVS 或 REP STOS 指令触发该问题。

利用条件与风险

利用前提是攻击者拥有 guest 虚拟机内的特权(如 root),可访问本地 APIC 等 MMIO 区域。实战中可导致宿主机及其上所有其他 guest 崩溃,形成拒绝服务。

修复建议

升级至 illumos-gate commit 696ecf8d 或之后版本以修复。临时缓解措施暂无公开信息。

原始情报

A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefixed MOVS or STOS instruction that accesses guest MMIO, vie_emulate_movs() and vie_emulate_stos() in usr/src/uts/intel/io/vmm/vmm_instruction_emul.c do not clear the VIES_REPEAT status flag on the final iteration. For MMIO regions emulated in the kernel (the local APIC, I/O APIC and HPET), the stale flag causes a VERIFY assertion in vie_advance_pc() to fail, and the host panics. A privileged user within a guest VM can issue a REP MOVS or REP STOS instruction against the local APIC page to cause a denial of service of the host and every other guest running on it. The flaw has existed since 2020 (illumos-gate commit e0c0d44e), and affects any illumos distribution prior to illumos-gate commit 696ecf8d.