Executive brief
A vulnerability exists in the Linux kernel's handling of AMD Secure Nested Paging (SNP), a technology used to protect data in virtual machines. Under certain conditions, the system fails to properly clear sensitive data from the processor's temporary memory (cache) when switching memory states. This could potentially allow an attacker to access or manipulate private data belonging to a secure virtual machine, compromising the confidentiality and integrity of the guest environment.
Technical details
A cache coherency vulnerability was identified in the x86/sev component of the Linux kernel when using AMD SEV-SNP. The issue occurs during the transition of memory pages to a 'private' state; without explicit cache line eviction, stale data may persist in the cache. The fix implements a software mitigation that touches the first and last byte of each 4K page being validated to force cache eviction, unless the CPUID bit COHERENCY_SFW_NO is set. This vulnerability could be exploited by a local attacker to bypass memory isolation boundaries provided by SNP. Patches have been released across multiple stable kernel branches including 6.1.y, 6.6.y, and 6.12.y.
Affected products
- Linux Linux Kernel 5.19 to 6.15.10
Timeline
- 2025-08-19: advisory: CVE-2025-38560 published by NVD
- 2025-08-15: patched: Fix committed to Linux stable tree by Greg Kroah-Hartman
References
- https://git.kernel.org/stable/c/1fb873971e23c35c53823c62809a474a92bc3022
- https://git.kernel.org/stable/c/1fec416c03d0a64cc21aa04ce4aa14254b017e6a
- https://git.kernel.org/stable/c/7b306dfa326f70114312b320d083b21fa9481e1e
- https://git.kernel.org/stable/c/a762a4c8d9e768b538b3cc60615361a8cf377de8
- https://git.kernel.org/stable/c/aed15fc08f15dbb15822b2a0b653f67e76aa0fdf
- https://git.kernel.org/stable/c/f92af52e6dbd8d066d77beba451e0230482dc45b
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html