Database/Kernel, userspace & hypervisor

Linux KVM - GHCB v2+ scratch area location enforcement: KVM did not require the GHCB software scratch area to live
Impact
KVM did not require the GHCB software scratch area to live inside the GHCB's own shared buffer when GHCB v2+ is in use, as the spec demands. A guest can therefore point the scratch area at memory outside the shared region and get the host to read or write there on its behalf - a confused-deputy path from a confidential guest into host memory. Guest-to-host escape shape, and the CVSS 8.8 reflects it.
Who can reach it
From inside an SEV-ES/SNP guest via the GHCB protocol - tenant-reachable with no host privilege.
What to do
Fixed in the Linux kernel - KVM/x86 SEV code or the ccp/PSP driver. Take the distro kernel update (RHEL/Rocky, Ubuntu, SLES) and **reboot the host**; SEV/SNP hypervisor paths cannot be live-patched in any meaningful way, and SNP platform init/shutdown is not safe to cycle under running guests. Drain confidential-VM tenants, reboot, then re-admit. No firmware, VBIOS or AGESA step needed, which makes this one of the cheaper classes of SEV fix to roll out. Top-of-queue for any node hosting tenant-supplied confidential VMs.
References
Related entries
- PREVAIL: ALU32 arithmetic on pointers passes verification but truncates the pointer at runtimeCVE-2026-53706 · PREVAIL eBPF verifier (ALU32 ADD/SUB on pointer registers)High
- Linux kernel (arch/x86/kvm/mmu): A guest that creates a hugepage mapping extending below the bounds of a memslot makesCVE-2026-63807 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (net/xfrm): Transport-mode reinjection stashes a network-namespace pointer in the socket buffer's controlCVE-2026-63919 · Linux kernel (net/xfrm)High
- Linux kernel (arch/x86/kvm/svm): KVM read Page State Change entries and indices out of a guest-writable buffer moreCVE-2026-63937 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (drivers/vfio/pci): Vfio-pci exports a dma-buf over BAR memory without confirming those BAR resources wereCVE-2026-64042 · Linux kernel (drivers/vfio/pci)High
- Linux kernel crypto/ecc: missing carry in 128-bit accumulation corrupts ECC arithmetic at a boundaryCVE-2026-64313 · Linux kernel crypto/ecc (vli multiplication carry handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.