Database/Kernel, userspace & hypervisor

Linux kernel (arch/x86/kvm/svm): A confidential guest can hand KVM a port-I/O request with length or count zero
Impact
A confidential guest can hand KVM a port-I/O request with length or count zero, underflowing the size arithmetic that sizes the GHCB scratch area and pushing host-kernel accesses past the end of that buffer. The SEV-ES/SNP boundary that is supposed to keep an encrypted tenant away from host memory is what fails here.
Who can reach it
Driven entirely from inside a running SEV-ES / SEV-SNP guest: the guest issues a VMGEXIT port-I/O exit through its own GHCB with len/count of 0. Needs no host account and no VMM cooperation. Only applies to nodes actually running AMD SEV-ES/SNP guests under kvm_amd; a container tenant with no VM of its own cannot reach it.
What to do
Boot a kernel carrying the referenced stable commits - the kernel CNA published no fixed release string for this record, so match on the commit in your distro's changelog. Interim control: stop scheduling SEV-ES/SNP guests on unpatched nodes, or run those tenants as ordinary (non-confidential) VMs until the fix lands.
References
Related entries
- Linux kernel (arch/x86/kvm/svm): When a GSI route changed to something that cannot be posted, KVM only fixed up theCVE-2025-37885 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): KVM read Page State Change entries and indices out of a guest-writable buffer moreCVE-2026-63937 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): Hardware ignores the low five bits of CR3 when loading PDPTEs, but KVM's nested SVMCVE-2024-50115 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): If AVIC is inhibited while a nested guest is running, KVM leaves the x2APIC MSRsCVE-2026-74516 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): VMLOAD/VMSAVE executed by an L2 guest and not intercepted by L1 were emulated againstCVE-2026-43133 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel (arch/x86/kvm/svm): The SEV debug-encrypt path bounds each iteration by the source page offset but not theCVE-2026-63794 · Linux kernel (arch/x86/kvm/svm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.