CVE-2025-21839 is a Linux kernel KVM/x86 virtualization flaw in debug register 6 (DR6) handling. When KVM has disabled debug-register interception because host userspace is not debugging the guest, a guest may modify DR6 directly in hardware. If the subsequent VM exit takes a fast path, common VM-exit handling can preserve stale vcpu->arch.dr6 state while the VMX or SVM vCPU run path reloads hardware DR6 from that stale value. This overwrites the guest's actual DR6 value. The defect is especially likely to manifest in nested VMX environments, where the interval between an L1 write to DR6 and its subsequent use can be substantially longer. The fix moves conditional loading of the guest DR6 value so that it occurs only before entering the core vCPU run loop.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux kernel KVM x86 vulnerability related to DR6 handling before entering the vcpu_run loop.
A Linux kernel KVM x86 debug-register state-management flaw in which stale DR6 state can overwrite a guest's hardware DR6 value during VM exits, particularly in nested VMX environments.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.