PT-2026-61256 · Linux+1 · Linux Kernel+1

CVE-2026-63939

·

Published

2026-07-19

·

Updated

2026-09-07

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the KVM SEV implementation regarding the calculation of the maximum length of the in-GHCB scratch area. When the scratch area is located within the GHCB shared buffer, the system fails to correctly set the effective length based on the guest-provided pointer and the shared buffer end. While MMIO emulation was not affected because it used a maximum size, PSC requests only provide a minimum length to process the header. Without knowing the full size of the scratch area, the system is susceptible to buffer overflows during the processing of these requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63939
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu