Junglewise Threat Intelligence

CVE-2026-63937: Linux Kernel KVM TOCTOU in SEV Page State Change buffer

CVE-2026-63937 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's virtualization component (KVM) could allow a malicious guest virtual machine to interfere with the host system's memory management. By rapidly changing data in a shared buffer while the host is processing it, a guest might cause the host to perform incorrect operations. This could potentially lead to system instability or unauthorized access to host resources.

Technical details

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in arch/x86/kvm/svm/sev.c within the Linux kernel. The KVM SEV implementation failed to use proper memory barriers or atomic read operations when accessing the guest-provided Page State Change (PSC) buffer. A malicious guest can modify entries or indices in the buffer after the host has validated them but before they are used, potentially leading to out-of-bounds indexing or inconsistent state transitions. The fix introduces READ_ONCE() macros to ensure that values are read into local variables exactly once, preventing the compiler or hardware from re-fetching modified values from guest memory during processing. This issue affects systems utilizing AMD SEV-SNP.

Affected products

  • Linux Linux 6.11 to 6.12.92, 6.18.34, 7.0.11

Timeline

  • 2026-05-01: other: Patch authored
  • 2026-07-19: advisory: NVD publication date

References