Database/Firmware, BMC & network fabric
SEV-ES / SEV-SNP guest kernel - injection of virtual interrupts 0 and 14: An untrusted hypervisor can inject virtual
Impact
An untrusted hypervisor can inject virtual interrupts 0 (divide error) and 14 (page fault) into an SEV-SNP or SEV-ES guest at arbitrary points, reaching userspace signal handlers - in particular SIGFPE - inside the confidential VM. The Heckler research showed this class turning into authentication bypass inside the guest: inject an interrupt at the right instruction and a login check returns the wrong answer. The host never touches guest memory, so no memory-integrity mechanism catches it.
Who can reach it
Malicious hypervisor against its own guest. Requires timing precision but no guest vulnerability.
What to do
Fixed in the **guest** kernel, not the host - the hardening lives in the SEV-ES/SNP guest's #VC handler and interrupt entry code. That inverts the usual rollout: you can patch every hypervisor you own and still be exposed, because the protection has to be in the tenant's own VM image. As an operator your job is to ship updated confidential-guest images (or tell tenants which minimum kernel to run) and, where you can, enforce it as an admission requirement. Each guest picks the fix up on its next boot; no host reboot, no firmware update. Fixed by guest-kernel hardening (Linux 6.9+ restricts which interrupts a guest accepts from the hypervisor). Enable Restricted Injection where the platform and guest support it. Again this is a guest-image problem, so operators should publish a minimum kernel and gate confidential workloads on it rather than assuming host patching covers them.
References
Related entries
- Arista EOS and CVX: malformed CVX cluster messages crash the Sysdb agent and soft-reset the switchCVE-2025-5089 · Arista EOS / CloudVision eXchange (CVX) - Sysdb agent message handlingHigh
- Arista CVX: unexpected messages from a connected switch crash CVX agents and destabilise the clusterCVE-2025-5090 · Arista CloudVision eXchange (CVX) server - switch message handlingHigh
- Arista EOS: crafted DHCP packet restarts the DHCP relay service on client-facing VLANsCVE-2026-19655 · Arista EOS DHCP relay (Option 82 information option handling)High
- Cisco UCS UEFI Shell: memory write commands bypass Secure Boot validationCVE-2026-20293 · Cisco UCS server BIOS (UEFI Shell)High
- Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler): The async-event handler indexes a fixed arrayCVE-2026-31395 · Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler)High
- Junos OS MX Series PFE: micro-BFD flapping starves PFEMAN until the watchdog crashes and restarts the FPCCVE-2026-33800 · Juniper Junos OS on MX Series (Packet Forwarding Engine, PFEMAN micro-BFD event processing)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.