Impact
A reachable assertion in the illumos bhyve instruction emulator causes a kernel panic when a guest VM executes a REP‑prefixed MOVS or STOS instruction that accesses guest MMIO. The flag controlling repetition is not cleared correctly, so the verification assertion in vie_advance_pc() fails for MMIO regions such as the local APIC, I/O APIC, and HPET. The host kernel then aborts, taking all running guests offline. A privileged user inside a VM can trigger this by issuing the instruction against the local APIC page, resulting in host‑wide denial of service. The flaw leads to a crash but does not provide remote code execution or data theft.
Affected Systems
The vulnerability is present in OmniOS and any illumos distribution that has not incorporated commit 696ecf8d from illumos‑gate. All earlier releases of these projects that still use the vulnerable bhyve code path are affected. Users employing the default bhyve hypervisor on these platforms are at risk.
Risk and Exploitability
The CVSS score is 6.8, signifying a moderate severity. No EPSS score is reported, and the issue is not listed in CISA’s KEV catalog. Exploitation requires that the attacker possess privileged guest user rights, is running a bhyve virtual machine, and is able to inject a REP MOVS or REP STOS instruction targeting the local APIC MMIO region. The impact is a denial of service to the host and all other guests, but no direct code execution or data exfiltration is possible. The likelihood of exploitation depends on the presence of a privileged guest in a shared environment.
OpenCVE Enrichment