Junglewise Threat Intelligence

CVE-2026-63938: Linux Kernel KVM out-of-bounds access in SEV-SNP PSC processing

CVE-2026-63938 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's virtualization component (KVM) specifically affecting AMD SEV-SNP systems. The issue occurs when the system processes requests to change memory page states, failing to properly verify the size of the data buffer provided by a guest virtual machine. This could potentially allow a guest to interfere with the host system or access memory outside of its designated area, impacting the security and isolation of the virtualized environment.

Technical details

A vulnerability in 'arch/x86/kvm/svm/sev.c' within the Linux kernel's KVM subsystem arises from insufficient validation of Page State Change (PSC) requests. When a guest provides a pointer that is not aligned to the start of the Guest-Hypervisor Communication Block (GHCB) shared buffer, the effective size of the scratch area may be smaller than the maximum allowed size. The 'snp_begin_psc' function previously checked indices against a static maximum ('VMGEXIT_PSC_MAX_COUNT') rather than the actual available buffer length ('ghcb_sa_len'). An attacker operating a guest VM could potentially exploit this to cause a buffer overflow or out-of-bounds access on the host. The fix introduces a dynamic check to ensure 'max_nr_entries' is calculated based on the actual scratch area length.

Affected products

  • Linux Linux Kernel 6.11 to 7.1

Timeline

  • 2026-05-01: patched: Initial fix authored by Sean Christopherson
  • 2026-07-19: disclosed: CVE published to NVD

References

Related threats