Database/Kernel, userspace & hypervisor
VMware ESXi: Arbitrary kernel write from the VMX process - sandbox escape completing the zero-day chain
CVSS 8.2CVE-2025-22225Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Arbitrary kernel write from the VMX process - sandbox escape completing the zero-day chain [KEV]
Who can reach it
Tenant VM guest (chained after CVE-2025-22224)
What to do
ESXi patch + host reboot with evacuation
References
Related entries
- VMware ESXi: AD-integrated ESXi grants full host admin to any member of a re-created "ESX Admins" groupCVE-2024-37085 · VMware ESXiMedium
- OpenStack Nova: crafted QCOW header on a Flat-backend disk lets a tenant destroy host data on resizeCVE-2026-24708 · OpenStack Nova (Flat image backend, qemu-img resize)High
- Linux kernel (drivers/iommu/intel): A device that does not support ATS never gets inserted into the VT-d deviceCVE-2026-74355 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (arch/x86/kvm/svm): If AVIC is inhibited while a nested guest is running, KVM leaves the x2APIC MSRsCVE-2026-74516 · Linux kernel (arch/x86/kvm/svm)High
- Linux NFSD: NFSv2 SETATTR/CREATE useconds wrap to a bogus tv_nsec on 32-bit serversCVE-2026-89665 · Linux kernel NFSD (svcxdr_decode_sattr, NFSv2 useconds conversion)High
- Linux NFSD: bogus WARN_ON_ONCE fires on NFS re-export lookupsCVE-2026-89711 · Linux kernel NFSD (nfsd_mode_check WARN_ON_ONCE, NFS re-export)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.