Executive brief
A vulnerability in the Linux kernel's handling of AMD SEV-SNP virtual machines can cause significant timekeeping errors. In affected systems, the virtual machine's internal clock can drift away from the actual time, leading to system timers firing earlier than expected. This discrepancy can disrupt scheduled tasks, impact application stability, and potentially lead to a system crash (kernel panic) during startup.
Technical details
The vulnerability exists in the x86/sev component of the Linux kernel when using Secure TSC. The GUEST_TSC_FREQ MSR reports a nominal P0 frequency that deviates by approximately 0.2% from the actual mean TSC frequency. This mismatch leads to accumulated clock skew in SEV-SNP guest VMs, causing hrtimers to fire prematurely. Additionally, the initial implementation attempted to use ioremap_encrypted() during early TSC initialization, which triggers a kernel panic because kmalloc() is not yet available. The fix involves utilizing the TSC_FACTOR from the SEV firmware's secrets page to accurately calculate mean frequency and switching to early_ioremap_encrypted() to prevent the boot-time panic.
Affected products
- Linux Linux Kernel 6.14 to 6.15.7
Timeline
- 2025-06-30: patched: Initial patch submitted by AMD
- 2025-08-16: disclosed: CVE-2025-38508 assigned and published