CVE-2026-64307
Received Received - Intake

SEV SNP Configuration Failure in Linux Kernel

Vulnerability report for CVE-2026-64307, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-25

Last updated on: 2026-07-25

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) Sashiko notes: > if SEV initialization fails and KVM is actively running normal VMs, could a > userspace process trigger this code path via /dev/sev ioctls (e.g., > SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN > execution for an active VM trigger a general protection fault and crash the > host? Refuse to re-try initialization if SNP is not already initialized for SNP_CONFIG. This is technically an ABI break: before if SNP initialization failed it could be transparently retriggered by this ioctl, and if no VMs were running, everything worked fine. Hopefully this is enough of a corner case that nobody will notice, but someone does, there are a few options: * do something like symbol_get() for kvm and refuse to initialize if KVM is loaded * check each cpu's HSAVE_PA for non-zero data before re-initializing * once initialization has failed, continue to refuse to initialize until the ccp module is unloaded

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-25
Last Modified
2026-07-25
Generated
2026-07-25
AI Q&A
2026-07-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves the CCP (Cryptographic Coprocessor) module not properly handling SNP (Secure Nested Paging) initialization failures. If SEV (Secure Encrypted Virtualization) initialization fails and KVM (Kernel-based Virtual Machine) is running VMs, a userspace process could trigger SNP_CONFIG via /dev/sev ioctls, potentially zeroing out MSR_VM_HSAVE_PA globally. This may cause a general protection fault during VMRUN execution, crashing the host.

Impact Analysis

If exploited, this vulnerability could lead to a host system crash due to a general protection fault during VM execution. It may also cause instability or denial of service if the SNP initialization failure is triggered while KVM is active. Users relying on SEV for secure virtualization could experience unexpected system failures.

Mitigation Strategies

Update the Linux kernel to the latest patched version to resolve the crypto ccp SNP initialization issue. Avoid using ioctl(SNP_CONFIG) if SEV initialization fails to prevent potential system crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64307. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart