Impact
An integer overflow in the calculation of the deadline for Hyper‑V synthetic timers in the Linux kernel can cause the timer to be armed with a time in the past. The timer then fires instantly and the kernel repeatedly resets and rearms the timer without ever allowing the reference counter to advance. This nonstop loop stalls kernel RCU grace‑period threads, which can lead to kernel stalls or out‑of‑memory conditions, effectively denying service to all processes on the affected CPUs.
Affected Systems
The likely affected systems are all Linux kernels running KVM with x86 Hyper‑V synthetic timers. No specific kernel version or patch level is listed, so any kernel that implements the stimer code prior to the commit that introduced the clamp is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderately high severity, but the EPSS score of < 1% implies a very low likelihood of exploitation at this time. The flaw is not yet listed in the CISA KEV catalog. It is inferred that an attacker would need the ability to set the HV_X64_MSR_STIMERi_COUNT MSR for a guest or host, which generally requires privileged access to the VM or to the KVM module. The likely attack vector is through privileged manipulation of these MSRs. Once the overflow is triggered, it can cause a stable livelock that starves kernel threads, leading to a denial‑of‑service state.
OpenCVE Enrichment
Debian DLA
Debian DSA