In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use
As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared buffer. Note, things like Page State Change (PSC) requests _rely_ on this behavior, as the guest can't provide a length when making the request, i.e. the size of the guest payload is bounded by the size of the shared buffer.
Failure to force usage of the GHCB, and a slew of other flaws, lets a malicious SNP guest corrupt host kernel heap memory, and leak host heap layout information.
setup_vmgexit_scratch() allocates a buffer via kvzalloc(exit_info_2), where exit_info_2 is guest-controlled. With exit_info_2=24, this yields a 24-byte allocation in kmalloc-cg-32 (32-byte slab objects). The buffer holds an 8-byte psc_hdr followed by 8-byte psc_entry structs, so only entries[0] and entries[1] are in-bounds.
snp_begin_psc() validates end_entry against VMGEXIT_PSC_MAX_COUNT (253) but NOT against the actual buffer size:
idx_end = hdr->end_entry;
if (idx_end >= VMGEXIT_PSC_MAX_COUNT) { // checks 253, not buffer snp_complete_psc(svm, ...); return 1; }
for (idx = idx_start; idx <= idx_end; idx++) { entry_start = entries[idx]; // OOB when idx >= 2
The guest sets end_entry=10+, causing the host to iterate entries[2+] which are OOB into adjacent slab objects. For each OOB entry:
- The host reads 8 bytes (OOB READ / info leak oracle) - If the data passes PSC validation, __snp_complete_one_psc() writes cur_page = 1 or 512 into the entry (OOB WRITE, sev.c:3806) - If validation fails, the error response reveals whether adjacent memory is zero vs non-zero (information disclosure to guest)
The guest controls allocation size (exit_info_2), entry range (cur_entry/end_entry), and can fire unlimited VMGEXITs to repeatedly hit different slab positions.
By exploiting the variety of bugs, a malicious SEV-SNP guest can: - OOB read adjacent kmalloc-cg-32 objects (heap layout disclosure) - OOB write cur_page bits into adjacent objects (heap corruption) - Trigger use-after-free conditions across VMGEXITs
E.g. with KASAN enabled, a single insmod of the PoC guest module produces 73 KASAN reports:
BUG: KASAN: slab-out-of-bounds in snp_begin_psc+0x126/0x890 Read of size 8 at addr ffff888219ffb5e0 by task qemu-system-x86/2199
BUG: KASAN: slab-out-of-bounds in snp_begin_psc+0x468/0x890 Write of size 8 at addr ffff888351566648 by task qemu-system-x86/2199
The buggy address belongs to the object at ffff888XXXXXXXXX which belongs to the cache kmalloc-cg-32 of size 32 The buggy address is located N bytes to the right of allocated 32-byte region [ffff888XXXXXXXXX, ffff888XXXXXXXXX)
Breakdown: 62 slab-out-of-bounds (reads + writes past allocation) 7 slab-use-after-free 4 use-after-free
All credit to Stan for the wonderful description and reproducer!
[sean: write changelog]
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.18Upgrade kernel6.18-modules-extra-commonUpgrade microvm-kernel6.18Upgrade kernel6.18-headersUpgrade kernel6.18-modules-extraUpgrade kernel6.18-tools-develUpgrade kernel6.18-toolsUpgrade kernel6.18-debuginfo-common-aarch64Upgrade kernel6.18-tools-debuginfoUpgrade python3-perf6.18-debuginfoUpgrade bpftool6.18-debuginfoUpgrade kernel6.18-develUpgrade bpftool6.18Upgrade perf6.18-debuginfoUpgrade python3-perf6.18Upgrade kernel6.18-debuginfo-common-x86_64Upgrade kernel6.18-debuginfoUpgrade kernel-livepatch-6.18.35-68.127Upgrade perf6.18 | Jul 21, 2026 | Jul 4, 2026 |
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jul 4, 2026 |
| Ubuntu | — | Upgrade linux-image-realtime-64kUpgrade linux-image-7.0.0-1008-oracleUpgrade linux-image-raspi-7.0Upgrade linux-image-azure-fdeUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-oracle-7.0Upgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-7.0.0-28-realtimeUpgrade linux-image-7.0.0-1015-raspi-realtimeUpgrade linux-image-awsUpgrade linux-image-generic-7.0Upgrade linux-image-gke-64kUpgrade linux-image-nvidia-bosUpgrade linux-image-oem-26.04Upgrade linux-image-oracleUpgrade linux-image-oem-24.04dUpgrade linux-image-oracle-64k-7.0Upgrade linux-image-7.0.0-28-realtime-64kUpgrade linux-image-nvidia-7.0Upgrade linux-image-oem-24.04aUpgrade linux-image-realtimeUpgrade linux-image-7.0.0-2016-nvidia-bosUpgrade linux-image-generic-hwe-26.04Upgrade linux-image-raspi-realtimeUpgrade linux-image-7.0.0-1011-oracleUpgrade linux-image-7.0.0-1008-oracle-64kUpgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-gke-64k-7.0Upgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-7.0.0-28-genericUpgrade linux-image-realtime-64k-hwe-26.04Upgrade linux-image-virtual-hwe-26.04Upgrade linux-image-azure-7.0Upgrade linux-image-oem-24.04cUpgrade linux-image-oracle-64kUpgrade linux-image-7.0.0-1009-awsUpgrade linux-image-raspiUpgrade linux-image-gcp-7.0Upgrade linux-image-nvidia-64kUpgrade linux-image-gcpUpgrade linux-image-oem-7.0Upgrade linux-image-7.0.0-1016-nvidiaUpgrade linux-image-7.0.0-1008-gcpUpgrade linux-image-realtime-hwe-26.04Upgrade linux-image-gke-64k-hwe-26.04Upgrade linux-image-7.0.0-1010-ibmUpgrade linux-image-7.0.0-1003-gkeUpgrade linux-image-virtualUpgrade linux-image-gcp-64k-7.0Upgrade linux-image-realtime-64k-7.0Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oem-24.04Upgrade linux-image-generic-64kUpgrade linux-image-gcp-64kUpgrade linux-image-nvidiaUpgrade linux-image-azureUpgrade linux-image-nvidia-64k-7.0Upgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-7.0.0-1003-gke-64kUpgrade linux-image-oem-24.04bUpgrade linux-image-7.0.0-1015-raspiUpgrade linux-image-7.0.0-1014-azureUpgrade linux-image-7.0.0-28-generic-64kUpgrade linux-image-7.0.0-1009-oemUpgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-7.0.0-1010-azureUpgrade linux-image-gke-7.0Upgrade linux-image-ibmUpgrade linux-image-azure-fde-7.0Upgrade linux-image-7.0.0-1009-aws-64kUpgrade linux-image-7.0.0-2016-nvidia-bos-64kUpgrade linux-image-raspi-realtime-7.0Upgrade linux-image-7.0.0-1016-nvidia-64kUpgrade linux-image-nvidia-bos-64kUpgrade linux-image-generic-64k-hwe-26.04Upgrade linux-image-ibm-7.0Upgrade linux-image-genericUpgrade linux-image-gke-hwe-26.04Upgrade linux-image-7.0.0-1011-oracle-64kUpgrade linux-image-oem-26.04aUpgrade linux-image-aws-64kUpgrade linux-image-7.0.0-1008-gcp-64kUpgrade linux-image-virtual-7.0Upgrade linux-image-nvidia-bos-7.0Upgrade linux-image-gkeUpgrade linux-image-aws-64k-7.0Upgrade linux-image-generic-64k-7.0Upgrade linux-image-aws-7.0Upgrade linux-image-realtime-7.0 | Jul 20, 2026 | Jul 4, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 28, 2026 | Jul 4, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub