PT-2026-61421 · Linux+1 · Linux Kernel+1

CVE-2026-64104

·

Published

2026-05-20

·

Updated

2026-09-07

CVSS v3.1

8.7

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the sev-guest component of the virt subsystem. When the set memory encrypted() or set memory decrypted() functions fail, the caller cannot determine the exact point of failure, leaving pages in an unknown state. Because these pages might remain unencrypted, they cannot be safely returned to the buddy allocator, which is the system's mechanism for managing physical memory pages. To prevent this, pages must not be freed; instead, proper accounting is performed by calling the snp leak pages() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14374
CVE-2026-64104
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu