VMSCAPE is an x86 Linux kernel speculative-execution vulnerability caused by insufficient branch-predictor isolation between a virtual machine guest and a userspace hypervisor such as QEMU. A malicious guest can poison branch-predictor state that userspace subsequently consumes after a VM exit, potentially enabling Spectre V2 information leakage across the guest-to-host userspace boundary. Existing mitigations protect the kernel and KVM from the malicious guest but do not provide the additional userspace protection. The fix conditionally issues an Indirect Branch Prediction Barrier (IBPB) after VM exit and before returning to userspace.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
95 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel vulnerability involving insufficient branch predictor isolation between virtual machine guests and userspace hypervisors. A malicious guest can poison branch predictors subsequently consumed by userspace. The fix conditionally issues an Indirect Branch Prediction Barrier (IBPB) after a VM exit and before returning to userspace, with potential performance overhead for workloads that frequently switch between hypervisor and userspace execution. The plugin reports medium severity and a CVSS v3 base score of 5.5.
A Linux virtualization vulnerability involving insufficient branch predictor isolation between a virtual machine guest and a userspace hypervisor. A malicious guest can poison branch predictors subsequently consumed by userspace. The fix conditionally issues an Indirect Branch Prediction Barrier (IBPB) after VM exit and before returning to userspace. The advisory recommends updating the linux package and related packages to version 6.1.153-1 or later and lists a CVSS v3 base score of 5.5.
A Linux kernel speculative-execution vulnerability affecting isolation of branch-predictor state between a virtual-machine guest and a userspace hypervisor. A malicious guest may poison branch-predictor state that is subsequently consumed by userspace after VM exit; the fix adds a conditional IBPB mitigation.
An Intel CPU 'VMScape' issue tracked as CVE-2025-40300 affecting KVM hosts. The content indicates embargoed kernel patches were prepared and later released through multiple SUSE security updates.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.