PT-2026-61254 · Linux+1 · Linux Kernel+1
CVE-2026-63937
·
Published
2026-07-19
·
Updated
2026-09-07
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the KVM SEV component where entries and indices are read from the guest-accessible Page State Change (PSC) buffer without proper synchronization. This lack of synchronization can lead to Time-of-Check to Time-of-Use (TOCTOU) bugs, which occur when a program checks a condition and then uses the result, but the condition changes between the check and the use. In this case, a misbehaving guest could modify the buffer while the kernel is processing it.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Ubuntu