CVE-2024-25743
published 2024-05-15CVE-2024-25743: In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler…
PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.24%
15.8th percentile
In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.9.7-1 (forky) | linux 6.9.7-1 (forky) |
| linux | linux_kernel | >= 0 < 6.9.7-1 | 6.9.7-1 |
| linux | linux_kernel | >= 0 < 6.9.7-1 | 6.9.7-1 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hw: amd: Instruction raise #VC exception at exit
vendor_redhat·2024-04-05·CVSS 7.1
CVE-2024-25743 [HIGH] hw: amd: Instruction raise #VC exception at exit
hw: amd: Instruction raise #VC exception at exit
In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.
A vulnerability was found in AMD SEV-SNP, where a malicious hypervisor can potentially break confidentiality and integrity of SEV-SNP on Linux guests by injecting interrupts. An attacker can inject interrupt 0x80, which is used by Linux for legacy 32-bit system calls, and arbitrarily change the value stored in EAX while a SEV VM is running.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not af
Debian
CVE-2024-25743: linux - In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual inte...
vendor_debian·2024·CVSS 7.1
CVE-2024-25743 [HIGH] CVE-2024-25743: linux - In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual inte...
In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 6.9.7-1)
sid: resolved (fixed in 6.9.7-1)
trixie: resolved (fixed in 6.9.7-1)
GHSA
GHSA-m82c-2r7m-qgcj: In the Linux kernel through 6
ghsa_unreviewed·2024-05-15
CVE-2024-25743 [HIGH] CWE-20 GHSA-m82c-2r7m-qgcj: In the Linux kernel through 6
In the Linux kernel through 6.7.2, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.
OSV
CVE-2024-25743: In the Linux kernel through 6
osv·2024-05-15·CVSS 7.1
CVE-2024-25743 [HIGH] CVE-2024-25743: In the Linux kernel through 6
In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.
No detection rules found.
No public exploits indexed.
arXiv
Attestable Builds: Compiling Verifiable Binaries on Untrusted Systems using Trusted Execution Environments
arxiv_fulltext·2025-10-24
Attestable Builds: Compiling Verifiable Binaries on Untrusted Systems using Trusted Execution Environments
Attestable Builds: Compiling Verifiable Binaries on Untrusted Systems using Trusted Execution Environments
Daniel Hugenroth
These authors contributed equally to this work.
[email protected]
0000-0003-3413-1722
University of Cambridge
Cambridge
United Kingdom
Mario Lins
[1]
[email protected]
0000-0003-1713-3347
Johannes Kepler University Linz
Linz
Austria
René Mayrhofer
[email protected]
0000-0003-1566-4646
Johannes Kepler University Linz
Linz
Austria
Alastair R. Beresford
[email protected]
0000-0003-0818-6535
University of Cambridge
Cambridge
United Kingdom
CCSXML
10002978.10003022.10003023
Security and privacy Software security engineering
500
10002978.10003006.10003007.10003009
Security and privacy Trusted computing
500
10002978.10003001.10003599.10011621
Security and
arXiv
Heckler: Breaking Confidential VMs with Malicious Interrupts
arxiv_fulltext·2024-04-04
Heckler: Breaking Confidential VMs with Malicious Interrupts
: Breaking Confidential VMs with Interrupts
Benedict Schlüter Supraja Sridhara Mark Kuhne Andrin Bertschi Shweta Shinde
ETH Zurich
## Abstract
5pt
Hardware-based Trusted execution environments (TEEs) offer
an isolation granularity of virtual machine abstraction. They provide confidential VMs (CVMs) that host security-sensitive code and data.
AMD SEV-SNP and Intel TDX enable CVMs and are now available on popular cloud platforms.
The untrusted hypervisor in these settings is in control of several resource management and configuration tasks, including interrupts.
We present , a new attack wherein the hypervisor injects malicious non-timer interrupts to break the confidentiality and integrity of CVMs.
Our insight is to use the interrupt handlers that have global effects, such that we can m
Bugzilla
CVE-2024-25742 CVE-2024-25743 hw: amd: Instruction raise #VC exception at exit
bugzilla·2024-03-21·CVSS 6.5
CVE-2024-25742 [MEDIUM] CVE-2024-25742 CVE-2024-25743 hw: amd: Instruction raise #VC exception at exit
CVE-2024-25742 CVE-2024-25743 hw: amd: Instruction raise #VC exception at exit
A vulnerability was found in AMD SEV-SNP (named "WeSee"), in this flaw, the hypervisor can inject a malicious #VC into a CPU that is executing a SEV-SNP VM at any time. Specifically, the hypervisor has the ability to inject external interrupts to the CPUs, including #VC which is yet another exception.
It is seen that SEV-SNP invokes the #VC exception handler in the VM without checking the authenticity of the root cause. Specifically, the VC handler does not check if the VM indeed executed an instruction that would legitimately cause the CPU to generate a #VC exception.
The VC handler performs sensitive operations of copying data between the VM and the hypervisor to emulate the semantics of the instruction tha
https://bugzilla.redhat.com/show_bug.cgi?id=2270836https://bugzilla.suse.com/show_bug.cgi?id=1223307https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=2270836https://bugzilla.suse.com/show_bug.cgi?id=1223307https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html
2024-05-15
Published