Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm/svm): Page State Change requests from a confidential guest were validated against the
Impact
Page State Change requests from a confidential guest were validated against the maximum possible scratch-area size rather than the size the guest's own pointer actually leaves available, so a guest can make the host walk PSC entries beyond the buffer. Result is guest-directed out-of-bounds access in host kernel memory from inside an encrypted VM.
Who can reach it
Issued by the guest itself: a SEV-SNP guest places its scratch pointer at a non-zero offset in the GHCB shared buffer and submits a PSC request whose entry indices run past the effective end. No host privilege, no VMM involvement. Conditional on the node running SEV-SNP guests on kvm_amd.
What to do
Boot a kernel with the referenced stable commits applied; the record carries no fixed release string, so verify by commit. Until then, keep SEV-SNP tenants off the affected nodes or downgrade those workloads to non-confidential VMs.
References
Related entries
- Linux kernel (arch/x86/kvm/svm): KVM computed the usable size of the guest-provided GHCB scratch area wrongly, so aCVE-2026-63939 · Linux kernel (arch/x86/kvm/svm)Critical
- Linux kernel (arch/x86/kvm/svm): A confidential guest can hand KVM a port-I/O request with length or count zeroCVE-2026-63940 · Linux kernel (arch/x86/kvm/svm)Critical
- Linux kernel (arch/x86/kvm/svm): When a GSI route changed to something that cannot be posted, KVM only fixed up theCVE-2025-37885 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): KVM read Page State Change entries and indices out of a guest-writable buffer moreCVE-2026-63937 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): Hardware ignores the low five bits of CR3 when loading PDPTEs, but KVM's nested SVMCVE-2024-50115 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): If AVIC is inhibited while a nested guest is running, KVM leaves the x2APIC MSRsCVE-2026-74516 · Linux kernel (arch/x86/kvm/svm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.