cbcvebase.
CVE-2025-21779
published 2025-02-27

CVE-2025-21779: In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Reject Hyper-V's SEND_IPI hypercalls if local APIC isn't in-kernel Advertise…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Reject Hyper-V's SEND_IPI hypercalls if local APIC isn't in-kernel Advertise support for Hyper-V's SEND_IPI and SEND_IPI_EX hypercalls if and only if the local API is emulated/virtualized by KVM, and explicitly reject said hypercalls if the local APIC is emulated in userspace, i.e. don't rely on userspace to opt-in to KVM_CAP_HYPERV_ENFORCE_CPUID. Rejecting SEND_IPI and SEND_IPI_EX fixes a NULL-pointer dereference if Hyper-V enlightenments are exposed to the guest without an in-kernel local APIC: dump_stack+0xbe/0xfd __kasan_report.cold+0x34/0x84 kasan_report+0x3a/0x50 __apic_accept_irq+0x3a/0x5c0 kvm_hv_send_ipi.isra.0+0x34e/0x820 kvm_hv_hypercall+0x8d9/0x9d0 kvm_emulate_hypercall+0x506/0x7e0 __vmx_handle_exit+0x283/0xb60 vmx_handle_exit+0x1d/0xd0 vcpu_enter_guest+0x16b0/0x24c0 vcpu_run+0xc0/0x550 kvm_arch_vcpu_ioctl_run+0x170/0x6d0 kvm_vcpu_ioctl+0x413/0xb20 __se_sys_ioctl+0x111/0x160 do_syscal1_64+0x30/0x40 entry_SYSCALL_64_after_hwframe+0x67/0xd1 Note, checking the sending vCPU is sufficient, as the per-VM irqchip_mode can't be modified after vCPUs are created, i.e. if one vCPU has an in-kernel local APIC, then all vCPUs have an in-kernel local APIC.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= 214ff83d4473a7757fa18a64dc7efe3b0e158486 < 61224533f2b61e252b03e214195d27d64b22989a61224533f2b61e252b03e214195d27d64b22989a
linuxlinux>= 214ff83d4473a7757fa18a64dc7efe3b0e158486 < 45fa526b0f5a34492ed0536c3cdf88b78380e4de45fa526b0f5a34492ed0536c3cdf88b78380e4de
linuxlinux>= 214ff83d4473a7757fa18a64dc7efe3b0e158486 < 5393cf22312418262679eaadb130d608c75fe6905393cf22312418262679eaadb130d608c75fe690
linuxlinux>= 214ff83d4473a7757fa18a64dc7efe3b0e158486 < 874ff13c73c45ecb38cb82191e8c1d523f0dc81b874ff13c73c45ecb38cb82191e8c1d523f0dc81b
linuxlinux>= 214ff83d4473a7757fa18a64dc7efe3b0e158486 < aca8be4403fb90db7adaf63830e27ebe787a76e8aca8be4403fb90db7adaf63830e27ebe787a76e8
linuxlinux>= 214ff83d4473a7757fa18a64dc7efe3b0e158486 < ca29f58ca374c40a0e69c5306fc5c940a0069074ca29f58ca374c40a0e69c5306fc5c940a0069074
linuxlinux>= 214ff83d4473a7757fa18a64dc7efe3b0e158486 < a8de7f100bb5989d9c3627d3a223ee1c863f3b69a8de7f100bb5989d9c3627d3a223ee1c863f3b69
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 4.20 < 6.1.1296.1.129
linuxlinux_kernel>= 6.13 < 6.13.46.13.4
linuxlinux_kernel>= 6.2 < 6.6.796.6.79
linuxlinux_kernel>= 6.7 < 6.12.166.12.16
msrcazl3_kernel_6.6.78.1-3_on_azure_linux_3.0
msrcazl3_kernel_6.6.79.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.179.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.