CVE-2025-40300PoC(debian / debian_linux)

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: x86/vmscape: Add conditional IBPB mitigation VMSCAPE is a vulnerability that exploits insufficient branch predictor isolation between a guest and a userspace hypervisor (like QEMU). Existing mitigations already protect kernel/KVM from a malicious guest. Userspace can additionally be protected by flushing the branch predictors after a VMexit. Since it is the userspace that consumes the poisoned branch predictors, conditionally issue an IBPB after a VMexit and before returning to userspace. Workloads that frequently switch between hypervisor and userspace will incur the most overhead from the new IBPB. This new IBPB is not integrated with the existing IBPB sites. For instance, a task can use the existing speculation control prctl() to get an IBPB at context switch time. With this implementation, the IBPB is doubled up: one at context switch and another before running userspace. The intent is to integrate and optimize these cases post-embargo. [ dhansen: elaborate on suboptimal IBPB solution ]

2.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • linux_kernel

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
debian_linuxlinux_kernel

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-18: 1PoC Mentioned / Linked · 2026-02-18: 1Technical Details · 2026-02-18: 102-18
Signal classification1 categories
PoC
1100.0%
Full discourse1 post
  • ‏⧢ ⦟ ⧢ ‏ ᅠ ᅠ ⧢ ⦟ ⧢ ᅠ‏ ᅠ ⧢ ⦟ ⧢ ⥋ ᅠᅠ ᅠ⧢⧟⧢ ᅠᅠᅠ‏ᅠᅠᅠ‏@EVEZ666
    PoC

    VMScape (CVE-2025-40300): ETH Zurich broke KVM isolation Guest poisons branch predictor → QEMU speculatively leaks host memory on VM exit 32 bytes/sec on Zen 4. 4KB encryption key in 12 min. Works PAST existing Spectre mitigations.

    Post summary

    A PoC demonstrates that CVE‑2025‑40300 can break KVM isolation via branch‑predictor poisoning, leaking host memory, but no active exploitation or patch information is disclosed.

    1000084
    1.5K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.17--
OSlinuxlinux_kernel6.17--
OSlinuxlinux_kernel6.17--
OSlinuxlinux_kernel6.17--
OSlinuxlinux_kernel6.17--

Explore more