Description
A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefixed MOVS or STOS instruction that accesses guest MMIO, vie_emulate_movs() and vie_emulate_stos() in usr/src/uts/intel/io/vmm/vmm_instruction_emul.c do not clear the VIES_REPEAT status flag on the final iteration. For MMIO regions emulated in the kernel (the local APIC, I/O APIC and HPET), the stale flag causes a VERIFY assertion in vie_advance_pc() to fail, and the host panics. A privileged user within a guest VM can issue a REP MOVS or REP STOS instruction against the local APIC page to cause a denial of service of the host and every other guest running on it. The flaw has existed since 2020 (illumos-gate commit e0c0d44e), and affects any illumos distribution prior to illumos-gate commit 696ecf8d.
Published: 2026-10-09
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A reachable assertion in the illumos bhyve instruction emulator causes a kernel panic when a guest VM executes a REP‑prefixed MOVS or STOS instruction that accesses guest MMIO. The flag controlling repetition is not cleared correctly, so the verification assertion in vie_advance_pc() fails for MMIO regions such as the local APIC, I/O APIC, and HPET. The host kernel then aborts, taking all running guests offline. A privileged user inside a VM can trigger this by issuing the instruction against the local APIC page, resulting in host‑wide denial of service. The flaw leads to a crash but does not provide remote code execution or data theft.

Affected Systems

The vulnerability is present in OmniOS and any illumos distribution that has not incorporated commit 696ecf8d from illumos‑gate. All earlier releases of these projects that still use the vulnerable bhyve code path are affected. Users employing the default bhyve hypervisor on these platforms are at risk.

Risk and Exploitability

The CVSS score is 6.8, signifying a moderate severity. No EPSS score is reported, and the issue is not listed in CISA’s KEV catalog. Exploitation requires that the attacker possess privileged guest user rights, is running a bhyve virtual machine, and is able to inject a REP MOVS or REP STOS instruction targeting the local APIC MMIO region. The impact is a denial of service to the host and all other guests, but no direct code execution or data exfiltration is possible. The likelihood of exploitation depends on the presence of a privileged guest in a shared environment.

Generated by OpenCVE AI on October 9, 2026 at 15:44 UTC.

Remediation

Vendor Solution

Update your illumos distribution to one that includes the fix for this issue.


Vendor Workaround

No configuration-level mitigation is available. In-kernel emulation of the local APIC, I/O APIC and HPET cannot be disabled on affected systems. Update to an illumos distribution that includes the fix.


OpenCVE Recommended Actions

  • Deploy a recent illumos release that includes the bhyve code update in commit 696ecf8d.
  • If immediate upgrade is not feasible, cease use of bhyve on the affected system until the patch is applied.
  • Consider migrating critical workloads away from this hypervisor or isolating untrusted guests in separate hosts to prevent a single faulty guest from crashing the host.

Generated by OpenCVE AI on October 9, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Illumos
Illumos illumos-gate
Omnios
Omnios omnios
Vendors & Products Illumos
Illumos illumos-gate
Omnios
Omnios omnios

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefixed MOVS or STOS instruction that accesses guest MMIO, vie_emulate_movs() and vie_emulate_stos() in usr/src/uts/intel/io/vmm/vmm_instruction_emul.c do not clear the VIES_REPEAT status flag on the final iteration. For MMIO regions emulated in the kernel (the local APIC, I/O APIC and HPET), the stale flag causes a VERIFY assertion in vie_advance_pc() to fail, and the host panics. A privileged user within a guest VM can issue a REP MOVS or REP STOS instruction against the local APIC page to cause a denial of service of the host and every other guest running on it. The flaw has existed since 2020 (illumos-gate commit e0c0d44e), and affects any illumos distribution prior to illumos-gate commit 696ecf8d.
Title Reachable assertion in illumos bhyve REP string instruction emulation allows guest to panic host
Weaknesses CWE-617
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:P/AU:Y/R:A/V:C'}


Subscriptions

Illumos Illumos-gate
Omnios Omnios
cve-icon MITRE

Status: PUBLISHED

Assigner: illumos

Published:

Updated: 2026-10-09T16:46:08.116Z

Reserved: 2026-09-29T18:57:32.373Z

Link: CVE-2026-102916

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T15:17:06.560

Modified: 2026-10-09T16:35:35.900

Link: CVE-2026-102916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T16:00:09Z

Weaknesses