Database/Firmware, BMC & network fabric

Linux KVM - VMSA sync on an already-launched SEV vCPU: KVM allowed synchronising vCPU state into the VMSA
Impact
KVM allowed synchronising vCPU state into the VMSA after the VMSA had already been encrypted and the guest launched. Writing to an encrypted VMSA behind the guest's back corrupts the confidential vCPU state that attestation covered - the guest is no longer the thing that was measured, and the failure is silent rather than loud.
Who can reach it
Via the KVM ioctl surface, from the VMM process managing the guest.
What to do
Fixed in the Linux kernel - KVM/x86 SEV code or the ccp/PSP driver. Take the distro kernel update (RHEL/Rocky, Ubuntu, SLES) and **reboot the host**; SEV/SNP hypervisor paths cannot be live-patched in any meaningful way, and SNP platform init/shutdown is not safe to cycle under running guests. Drain confidential-VM tenants, reboot, then re-admit. No firmware, VBIOS or AGESA step needed, which makes this one of the cheaper classes of SEV fix to roll out.
References
Related entries
- Linux bnxt_en driver (backing store type from firmware response): A second firmware-controlled-index bug in the sameCVE-2026-43034 · Linux bnxt_en driver (backing store type from firmware response)Medium
- Linux kernel (drivers/infiniband/hw/irdma): A tenant that asks for a user QP while declaring a zero-size work-queueCVE-2026-68418 · Linux kernel (drivers/infiniband/hw/irdma)Medium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/lib): Every memory-key allocation carrying a steering-tag hintCVE-2026-72006 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/lib)Medium
- Dell OMSA: missing authentication on a critical function lets a local user crash the management agentCVE-2026-81441 · Dell OpenManage Server Administrator (OMSA) managed-node agentMedium
- Dell OMSA: partial string comparison flaw lets a low-privileged local user cause a denial of serviceCVE-2026-81479 · Dell OpenManage Server Administrator (OMSA) managed-node agentMedium
- Opengear console server (serial port logging): Stored XSS injected from a device *connected to* a serial portCVE-2019-14456 · Opengear console server (serial port logging)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.