CVE-2026-102916
Received Received - Intake

Assertion Failure in illumos bhyve MMIO Emulation

Vulnerability report for CVE-2026-102916, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: illumos

Description

A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefixed MOVS or STOS instruction that accesses guest MMIO, vie_emulate_movs() and vie_emulate_stos() in usr/src/uts/intel/io/vmm/vmm_instruction_emul.c do not clear the VIES_REPEAT status flag on the final iteration. For MMIO regions emulated in the kernel (the local APIC, I/O APIC and HPET), the stale flag causes a VERIFY assertion in vie_advance_pc() to fail, and the host panics. A privileged user within a guest VM can issue a REP MOVS or REP STOS instruction against the local APIC page to cause a denial of service of the host and every other guest running on it. The flaw has existed since 2020 (illumos-gate commit e0c0d44e), and affects any illumos distribution prior to illumos-gate commit 696ecf8d.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
illumos illumos-gate e0c0d44e917080841514d0dd031a696c74e8c435
OmniOS OmniOS any
OmniOS OmniOS r151058
OmniOS OmniOS r151056
OmniOS OmniOS r151054

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a reachable assertion flaw in the illumos bhyve instruction emulator. It allows a guest VM to crash the host system by exploiting a stale status flag during the emulation of REP-prefixed MOVS or STOS instructions that access guest MMIO. The issue occurs because vie_emulate_movs() and vie_emulate_stos() do not clear the VIES_REPEAT flag on the final iteration, leading to a failed assertion in vie_advance_pc() for MMIO regions like the local APIC, I/O APIC, and HPET.

Detection Guidance

This vulnerability is specific to illumos-based systems and involves the bhyve instruction emulator. Detection requires checking the illumos-gate version for the presence of the flaw (commit e0c0d44e or earlier). No direct commands are provided in the context to detect active exploitation.

Impact Analysis

A privileged user within a guest VM can trigger this flaw to cause a denial of service on the host and all other guest VMs running on it. This results in host system crashes, disrupting all virtual machines and services dependent on the host.

Mitigation Strategies

Update illumos-gate to commit 696ecf8d or later to resolve the flaw. If immediate patching is not possible, restrict access to guest VMs to prevent privileged users from exploiting the issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102916. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart