Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm/svm): On AMD hosts that cannot report the next RIP, KVM's WRMSR/HLT/INVD fastpath has to
Impact
On AMD hosts that cannot report the next RIP, KVM's WRMSR/HLT/INVD fastpath has to decode the guest instruction, which reads guest memory - and it does so with interrupts disabled. A guest can therefore make the host kernel sleep in atomic context, which is a scheduling-while-atomic condition that can hang or crash the node; the impact is a shared-node DoS, not an escape.
Who can reach it
Guest-driven and unprivileged inside the VM: the tenant executes HLT, WRMSR or INVD from a page KVM must fault in to decode. Conditional on next-RIP being unavailable - older AMD silicon, or a host running with kvm_amd.nrips=0.
What to do
Update to a stable kernel with the linked fix (no fixed release enumerated; take the branch carrying commit da2a3c231f7f). Interim control: run on hosts with NRIPS support and never set kvm_amd.nrips=0.
References
Related entries
- Linux kernel (arch/x86/kvm/svm): Page State Change requests from a confidential guest were validated against theCVE-2026-63938 · Linux kernel (arch/x86/kvm/svm)Critical
- Linux kernel (arch/x86/kvm/svm): KVM computed the usable size of the guest-provided GHCB scratch area wrongly, so aCVE-2026-63939 · Linux kernel (arch/x86/kvm/svm)Critical
- Linux kernel (arch/x86/kvm/svm): A confidential guest can hand KVM a port-I/O request with length or count zeroCVE-2026-63940 · Linux kernel (arch/x86/kvm/svm)Critical
- Linux kernel (arch/x86/kvm/svm): When a GSI route changed to something that cannot be posted, KVM only fixed up theCVE-2025-37885 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): KVM read Page State Change entries and indices out of a guest-writable buffer moreCVE-2026-63937 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): Hardware ignores the low five bits of CR3 when loading PDPTEs, but KVM's nested SVMCVE-2024-50115 · Linux kernel (arch/x86/kvm/svm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.