PT-2026-61256 · Linux+1 · Linux Kernel+1
CVE-2026-63939
·
Published
2026-07-19
·
Updated
2026-09-07
CVSS v3.1
9.3
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the KVM SEV implementation regarding the calculation of the maximum length of the in-GHCB scratch area. When the scratch area is located within the GHCB shared buffer, the system fails to correctly set the effective length based on the guest-provided pointer and the shared buffer end. While MMIO emulation was not affected because it used a maximum size, PSC requests only provide a minimum length to process the header. Without knowing the full size of the scratch area, the system is susceptible to buffer overflows during the processing of these requests.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Ubuntu