Database/Firmware, BMC & network fabric

Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migration: KVM fetched source vCPUs from the wrong VM
Impact
KVM fetched source vCPUs from the wrong VM during SEV-ES intra-host migration. Operating on the wrong VM's vCPU structures during a confidential-VM migration is a cross-VM state confusion bug - exactly the failure class you do not want on the code path that moves encrypted guest state around.
Who can reach it
Through the KVM migration ioctl path, from the VMM.
What to do
Fixed in the Linux kernel. Take the distro kernel update (RHEL/Rocky, Ubuntu, SLES) and reboot the host - no firmware, VBIOS or AGESA step. On a GPU fleet this is a cordon, drain and rolling reboot; plan it as normal kernel maintenance.
References
Related entries
- tpm2-tools (tpm2_checkquote TPM2_GENERATED magic validation): tpm2_checkquote does not verify that the structureCVE-2024-29038 · tpm2-tools (tpm2_checkquote TPM2_GENERATED magic validation)Unscored
- tpm2-tools (tpm2_checkquote PCR selection handling): tpm2_checkquote does not validate the TPML_PCR_SELECTIONCVE-2024-29039 · tpm2-tools (tpm2_checkquote PCR selection handling)Unscored
- Linux kernel mlxbf_gige (BlueField out-of-band management NIC): NULL function-pointer dereference when the DPU'sCVE-2024-35907 · Linux kernel mlxbf_gige (BlueField out-of-band management NIC)Unscored
- Linux kernel mlx5_core eswitch ingress ACL: The eswitch ingress ACL - the table that enforces per-VF ingress policyCVE-2024-42142 · Linux kernel mlx5_core eswitch ingress ACLUnscored
- Juniper Junos OS (httpd / J-Web on QFX5120, EX, SRX, MX): Crafted HTTP requests to the web management process drive CPUCVE-2025-21601 · Juniper Junos OS (httpd / J-Web on QFX5120, EX, SRX, MX)Unscored
- Juniper Junos OS / Junos OS Evolved (rpd, BGP UPDATE): A crafted BGP UPDATE crashes the routing protocol daemon. In aCVE-2025-21602 · Juniper Junos OS / Junos OS Evolved (rpd, BGP UPDATE)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.