Database/Control plane, storage & DevOps
Linux crypto/ccp - SNP initialization on ioctl(SNP_COMMIT): The ccp driver initialised SNP from the SNP_COMMIT ioctl
Impact
The ccp driver initialised SNP from the SNP_COMMIT ioctl path, so a userspace process holding /dev/sev could drive SNP platform initialisation at a time the host was not expecting it - including while ordinary VMs are running. Triggering SNP platform state transitions underneath live guests is a route to destabilising the host and the confidential-computing state machine on it.
Who can reach it
Local, from a process with access to /dev/sev. On a well-run host that is the VMM or a management daemon, so the realistic path is a compromised control-plane component rather than a tenant.
What to do
Fixed in the Linux kernel - KVM/x86 SEV code or the ccp/PSP driver. Take the distro kernel update (RHEL/Rocky, Ubuntu, SLES) and **reboot the host**; SEV/SNP hypervisor paths cannot be live-patched in any meaningful way, and SNP platform init/shutdown is not safe to cycle under running guests. Drain confidential-VM tenants, reboot, then re-admit. No firmware, VBIOS or AGESA step needed, which makes this one of the cheaper classes of SEV fix to roll out. Worth checking who actually has /dev/sev open on your hosts - the permissions on that node are the difference between 'root only' and 'any service account that got a bit too much'.
References
Related entries
- Linux iommu/amd - IRQ-unsafe locking in guest domain allocation: An IRQ-unsafe lock taken during AMD IOMMU guest domainCVE-2026-68347 · Linux iommu/amd - IRQ-unsafe locking in guest domain allocationUnscored
- Linux perf/x86/amd/core - Branch Sampling enabled from the SVM reload path: Branch Sampling and Last Branch RecordCVE-2026-72325 · Linux perf/x86/amd/core - Branch Sampling enabled from the SVM reload pathUnscored
- Linux kernel NFSv4 client: a delayed FREE_STATEID can use a freed nfs_serverCVE-2026-74730 · Linux kernel NFSv4 client (nfs_server lifetime across FREE_STATEID)Unscored
- NVMe/TCP host: a short read is reported to userspace as a complete readCVE-2026-89480 · Linux kernel nvme-tcp host (short-read completion accounting)Unscored
- NVMe/TCP host: a malicious target can read host kernel memory by sending R2T for a READCVE-2026-89481 · Linux kernel nvme-tcp host (R2T direction check)Unscored
- NVMe/TCP host: C2HData for a WRITE_ZEROES command writes into a stale iteratorCVE-2026-89482 · Linux kernel nvme-tcp host (C2HData receive gate, WRITE_ZEROES path)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.