Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102916— Reachable assertion in illumos bhyve REP string instruction emulation allows guest to panic host

Quick assessment

Affected
illumos illumos-gate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 illumos 的 bhyve 指令模拟器中存在一个可达的断言错误,可能导致虚拟机(guest)使宿主机(host)崩溃。当模拟带有 REP 前缀的 MOVS 或 STOS 指令且这些指令访问客户机内存映射 I/O(MMIO)时,函数 vie_emulate_movs() 和 vie_emulate_stos()(位于 usr/src/uts/intel/io/vmm/vmm_instruction_emul.c 文件中)在最后一次迭代时未能清除 VIES_REPEAT 状态标志。对于在内核中模拟的 MMIO

CVSS 6.8 · Medium

Affected Version Matrix 5

VendorProduct Version RangeStatus
illumos illumos-gate e0c0d44e917080841514d0dd031a696c74e8c435< 696ecf8debceed9dc33937d8c8e111e4aeebfdae affected
OmniOS OmniOS any< r151054 affected
r151058< r151058w affected
r151056< r151056aw affected
r151054< r151054bw affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102916

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Reachable assertion in illumos bhyve REP string instruction emulation allows guest to panic host
Source: CVE Program / CVE List V5
Vulnerability Description
A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefixed MOVS or STOS instruction that accesses guest MMIO, vie_emulate_movs() and vie_emulate_stos() in usr/src/uts/intel/io/vmm/vmm_instruction_emul.c do not clear the VIES_REPEAT status flag on the final iteration. For MMIO regions emulated in the kernel (the local APIC, I/O APIC and HPET), the stale flag causes a VERIFY assertion in vie_advance_pc() to fail, and the host panics. A privileged user within a guest VM can issue a REP MOVS or REP STOS instruction against the local APIC page to cause a denial of service of the host and every other guest running on it. The flaw has existed since 2020 (illumos-gate commit e0c0d44e), and affects any illumos distribution prior to illumos-gate commit 696ecf8d.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:P/AU:Y/R:A/V:C
Source: CVE Program / CVE List V5
Vulnerability Type
可达断言
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
illumos illumos-gate e0c0d44e917080841514d0dd031a696c74e8c435 ~ 696ecf8debceed9dc33937d8c8e111e4aeebfdae -
OmniOS OmniOS any ~ r151054 -

II. Public POCs for CVE-2026-102916

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102916

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-102916 (1)

Vendor Advisories for CVE-2026-102916 (1)

Mailing List Discussions for CVE-2026-102916 (1)

Same Patch Batch · illumos · 2026-10-09 · 6 CVEs total

CVE-2026-104112 6.8 MEDIUM Missing release of passed file descriptors in illumos nscd allows local users to exhaust k
CVE-2026-104114 5.4 MEDIUM NULL pointer dereference in illumos nwamd door handler allows local users to crash the dae
CVE-2026-104115 5.4 MEDIUM Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the
CVE-2026-104117 1.9 LOW Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP grou
CVE-2026-104116 1.9 LOW Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enum

IV. Related Vulnerabilities

V. Comments for CVE-2026-102916

No comments yet


Leave a comment