Posted by Jinu Kim on Sep 29 Hello, I found a guest-triggerable host-kernel panic in KVM's x86 shadow MMU. I reproduced it on Linux 6.1.74 and on pre-fix mainline. An attacker with kernel-level control of an L1 guest can reach it; my reproducer uses nested VMX/EPT, Q35 SMM, and two vCPUs.

Read the full article at oss-security →