PT-2026-61110 · Linux · Linux Kernel
CVE-2026-63794
·
Published
2026-07-19
·
Updated
2026-07-20
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the Linux kernel KVM SVM implementation within the
sev dbg crypt() function. In the encryption path handled by sev dbg encrypt user(), the per-iteration transfer length is bounded by the source page offset but not by the destination page offset. When the destination offset is greater than the source offset, the system performs a read-modify-write using a single-page intermediate buffer. This can lead to a buffer overflow where the PSP writes beyond the 4096-byte allocation of the dst tpage buffer, and subsequent memory copy operations overflow by up to 15 bytes.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel