Buffer Overflow Vulnerability in KVM by AMD Affects Linux Kernel
CVE-2026-63794
What is CVE-2026-63794?
A vulnerability exists in the KVM module of the Linux kernel, where insufficient bounds checking in the sev_dbg_crypt function can lead to a buffer overflow condition. Specifically, when the destination page offset exceeds the source page offset, the encryption process may attempt to write beyond allocated memory bounds. This flaw can arise in scenarios involving the secure encryption of virtualized environments, potentially leading to data corruption or unexpected behavior in the guest systems. To mitigate this vulnerability, the transfer length must be appropriately limited by the destination offset, as already enforced in related functions.
Affected Version(s)
Linux 24f41fb23a39bc2b6f190dcef35a5813a4bf183a
Linux 24f41fb23a39bc2b6f190dcef35a5813a4bf183a < 64f2449841ffc7d203183aa4c748c9c77951ecc5
Linux 24f41fb23a39bc2b6f190dcef35a5813a4bf183a < 9349b50f4b11f135fe73b56cb2c2c872d8bc71d7