CVE-2026-64309
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2026
Last modified:
25/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)<br />
<br />
Sashiko notes:<br />
<br />
> if SEV initialization fails and KVM is actively running normal VMs, could a<br />
> userspace process trigger this code path via /dev/sev ioctls (e.g.,<br />
> SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN<br />
> execution for an active VM trigger a general protection fault and crash the<br />
> host?<br />
<br />
The SNP_COMMIT command does not require the firmware to be in any<br />
particular state. Skip initializing it if it was previously uninitialized.<br />
<br />
The SEV-SNP firmware specification doc 56860 does not mention SNP_COMMIT in<br />
Table 5 as a command that is allowed in the UNINIT state, but it is in fact<br />
allowed and a future documentation update will reflect that.



