CVE-2026-64307 Details
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) Sashiko notes: > if SEV initialization fails and KVM is actively running normal VMs, could a > userspace process trigger this code path via /dev/sev ioctls (e.g., > SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN > execution for an active VM trigger a general protection fault and crash the > host? Refuse to re-try initialization if SNP is not already initialized for SNP_CONFIG. This is technically an ABI break: before if SNP initialization failed it could be transparently retriggered by this ioctl, and if no VMs were running, everything worked fine. Hopefully this is enough of a corner case that nobody will notice, but someone does, there are a few options: * do something like symbol_get() for kvm and refuse to initialize if KVM is loaded * check each cpu's HSAVE_PA for non-zero data before re-initializing * once initialization has failed, continue to refuse to initialize until the ccp module is unloaded
A vulnerability exists in the Linux kernel's crypto CCP driver related to the initialization of Secure Nested Paging (SNP) when handling the SNP_CONFIG ioctl. If the SEV initialization fails while KVM is running virtual machines, a userspace process could potentially exploit this issue. This could lead to zeroing out the MSR_VM_HSAVE_PA register, causing a general protection fault and crashing the host during the next VMRUN execution for an active VM. The vulnerability arises because the ioctl can be used to reinitialize SNP, creating a risk of disrupting the virtual machine's operation.
No specific remediation is mentioned, but users can monitor for updates in the Linux kernel stable tree where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/08f0e65e784c4b20e6e620dd4f68d8636073a3d2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/20f548cdac94860a164e5ebba4f7e4a01051cb06 | kernel.org | Patch |
| https://git.kernel.org/stable/c/345a6e869b33687e9268044bcaeeefd7c61da675 | kernel.org | Patch |
| https://git.kernel.org/stable/c/441ea32cf2755a0dc593557056b00b7caa0651f5 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.12.75, < 6.12.97 >= 6.16, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |