GPU VulnDB

Database/Firmware, BMC & network fabric

Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migration: KVM fetched source vCPUs from the wrong VM

CVE-2023-54296Firmware, BMC & network fabriccurated

Impact

KVM fetched source vCPUs from the wrong VM during SEV-ES intra-host migration. Operating on the wrong VM's vCPU structures during a confidential-VM migration is a cross-VM state confusion bug - exactly the failure class you do not want on the code path that moves encrypted guest state around.

Who can reach it

Through the KVM migration ioctl path, from the VMM.

What to do

Fixed in the Linux kernel. Take the distro kernel update (RHEL/Rocky, Ubuntu, SLES) and reboot the host - no firmware, VBIOS or AGESA step. On a GPU fleet this is a cordon, drain and rolling reboot; plan it as normal kernel maintenance.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.