Bug 2502399 (CVE-2026-63937)
| Summary: | CVE-2026-63937 kernel: KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) with Secure Encrypted Virtualization (SEV). This time-of-check to time-of-use (TOCTOU) vulnerability exists when KVM processes the guest-accessible Page State Change (PSC) buffer. A misbehaving guest could exploit this timing issue by modifying the buffer after it has been checked but before it is used, potentially leading to an impact on the integrity of the virtualized environment.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-07-19 16:06:06 UTC
|