PT-2026-61254 · Linux · Linux

CVE-2026-63937

·

Published

2026-07-19

·

Updated

2026-07-19

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Use READ ONCE() when reading entries/indices from PSC buffer
Use READ ONCE() when reading entries/indices from the guest-accessible Page State Change buffer to defend against TOCTOU bugs.
Don't bother with READ ONCE()/WRITE ONCE() for cases where KVM is writing (and not consuming the result!), as the guest isn't supposed to touch the buffer while it's being processed. I.e. using READ ONCE() is all about protecting against misbehaving guests.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63937

Affected Products

Linux