Executive brief
A vulnerability was identified in the Linux kernel's virtualization component (KVM) specifically affecting AMD SEV (Secure Encrypted Virtualization). The system failed to properly handle certain input/output requests with a length of zero, which could lead to internal errors or unexpected behavior in the virtual machine manager. This issue has been resolved by ensuring the system explicitly ignores these invalid zero-length requests.
Technical details
A vulnerability in the Linux kernel's KVM subsystem for AMD SVM/SEV was discovered where Port I/O requests with a length or count of '0' were not explicitly ignored. This lack of validation could lead to an integer underflow when calculating the length for the software scratch area during a VMGEXIT. The fix introduces explicit checks in `sev_handle_vmgexit` and `sev_es_string_io` within `arch/x86/kvm/svm/sev.c` to return early if the I/O size or total bytes are zero. This prevents potential memory corruption or kernel warnings triggered by invalid scratch area configurations. The issue affects systems using AMD SEV-ES or SEV-SNP virtualization.
Affected products
- Linux Linux 5.11 to 6.12.95, 6.18.35, 7.0.12
Timeline
- 2026-05-01: other: Patch authored by Sean Christopherson
- 2026-07-19: disclosed: CVE published to NVD