CVE-2026-64307
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2026
Last modified:
25/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)<br />
<br />
Sashiko notes:<br />
<br />
> if SEV initialization fails and KVM is actively running normal VMs, could a<br />
> userspace process trigger this code path via /dev/sev ioctls (e.g.,<br />
> SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN<br />
> execution for an active VM trigger a general protection fault and crash the<br />
> host?<br />
<br />
Refuse to re-try initialization if SNP is not already initialized for<br />
SNP_CONFIG.<br />
<br />
This is technically an ABI break: before if SNP initialization failed it<br />
could be transparently retriggered by this ioctl, and if no VMs were<br />
running, everything worked fine. Hopefully this is enough of a corner case<br />
that nobody will notice, but someone does, there are a few options:<br />
<br />
* do something like symbol_get() for kvm and refuse to initialize if KVM is<br />
loaded<br />
* check each cpu&#39;s HSAVE_PA for non-zero data before re-initializing<br />
* once initialization has failed, continue to refuse to initialize until<br />
the ccp module is unloaded



