Executive brief
A vulnerability was identified in the Linux kernel's virtualization component (KVM) for AMD processors. It occurs when the system handles encrypted memory debugging, potentially allowing a malicious actor with high privileges to cause a system crash or corrupt memory. This could impact the stability and security of virtual machine environments using AMD Secure Encrypted Virtualization (SEV).
Technical details
A page overflow exists in the sev_dbg_crypt() function within the KVM SVM implementation for AMD processors. The vulnerability is caused by a failure to bound the per-iteration transfer length by the destination page offset (PAGE_SIZE - d_off) during the ENCRYPT path. When the destination offset is greater than the source offset, the __sev_dbg_encrypt_user path performs a read-modify-write using a single-page intermediate buffer. If the rounded-up length exceeds the page size, the Platform Security Processor (PSP) writes beyond the 4096-byte buffer allocation, leading to a slab-use-after-free or out-of-bounds write. This can be triggered via the KVM_MEMORY_ENCRYPT_OP ioctl. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 7.0.0-smp
Timeline
- 2026-05-01: disclosed: Initial patch authored by Ashutosh Desai
- 2026-07-04: patched: Patch committed to stable trees by Greg Kroah-Hartman
- 2026-07-19: advisory: CVE-2026-63794 published
References
- https://git.kernel.org/stable/c/2753a097d1fe24c4351c608048612c74108aa89f
- https://git.kernel.org/stable/c/64f2449841ffc7d203183aa4c748c9c77951ecc5
- https://git.kernel.org/stable/c/720949ed666f34ff28ffdfe1471a5861d1e41fdf
- https://git.kernel.org/stable/c/78ee2d50185a037b3d2452a97f3dad69c3f7f389
- https://git.kernel.org/stable/c/889c2a9c59897ca912bf39df5bb92555a0a13df4
- https://git.kernel.org/stable/c/9349b50f4b11f135fe73b56cb2c2c872d8bc71d7
- https://git.kernel.org/stable/c/e1a0fe288dee07b7da25a71e007c1ecd1080315b