Project Subscriptions
No advisories yet.
Solution
Update your illumos distribution to one that includes the fix for this issue.
Workaround
No configuration-level mitigation is available. In-kernel emulation of the local APIC, I/O APIC and HPET cannot be disabled on affected systems. Update to an illumos distribution that includes the fix.
Fri, 09 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Illumos
Illumos illumos-gate Omnios Omnios omnios |
|
| Vendors & Products |
Illumos
Illumos illumos-gate Omnios Omnios omnios |
Fri, 09 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefixed MOVS or STOS instruction that accesses guest MMIO, vie_emulate_movs() and vie_emulate_stos() in usr/src/uts/intel/io/vmm/vmm_instruction_emul.c do not clear the VIES_REPEAT status flag on the final iteration. For MMIO regions emulated in the kernel (the local APIC, I/O APIC and HPET), the stale flag causes a VERIFY assertion in vie_advance_pc() to fail, and the host panics. A privileged user within a guest VM can issue a REP MOVS or REP STOS instruction against the local APIC page to cause a denial of service of the host and every other guest running on it. The flaw has existed since 2020 (illumos-gate commit e0c0d44e), and affects any illumos distribution prior to illumos-gate commit 696ecf8d. | |
| Title | Reachable assertion in illumos bhyve REP string instruction emulation allows guest to panic host | |
| Weaknesses | CWE-617 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: illumos
Published:
Updated: 2026-10-09T16:46:08.116Z
Reserved: 2026-09-29T18:57:32.373Z
Link: CVE-2026-102916
Updated: 2026-10-09T16:15:24.629Z
Status : Awaiting Analysis
Published: 2026-10-09T15:17:06.560
Modified: 2026-10-09T17:16:43.520
Link: CVE-2026-102916
No data.
OpenCVE Enrichment
Updated: 2026-10-09T16:00:09Z