Executive brief
A vulnerability was identified in the Linux kernel's virtualization component (KVM) specifically affecting AMD SEV-SNP systems. The issue occurs when the system processes requests to change memory page states, failing to properly verify the size of the data buffer provided by a guest virtual machine. This could potentially allow a guest to interfere with the host system or access memory outside of its designated area, impacting the security and isolation of the virtualized environment.
Technical details
A vulnerability in 'arch/x86/kvm/svm/sev.c' within the Linux kernel's KVM subsystem arises from insufficient validation of Page State Change (PSC) requests. When a guest provides a pointer that is not aligned to the start of the Guest-Hypervisor Communication Block (GHCB) shared buffer, the effective size of the scratch area may be smaller than the maximum allowed size. The 'snp_begin_psc' function previously checked indices against a static maximum ('VMGEXIT_PSC_MAX_COUNT') rather than the actual available buffer length ('ghcb_sa_len'). An attacker operating a guest VM could potentially exploit this to cause a buffer overflow or out-of-bounds access on the host. The fix introduces a dynamic check to ensure 'max_nr_entries' is calculated based on the actual scratch area length.
Affected products
- Linux Linux Kernel 6.11 to 7.1
Timeline
- 2026-05-01: patched: Initial fix authored by Sean Christopherson
- 2026-07-19: disclosed: CVE published to NVD