Buffer Overflow Vulnerability in KVM by AMD Affects Linux Kernel
CVE-2026-63794

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63794?

A vulnerability exists in the KVM module of the Linux kernel, where insufficient bounds checking in the sev_dbg_crypt function can lead to a buffer overflow condition. Specifically, when the destination page offset exceeds the source page offset, the encryption process may attempt to write beyond allocated memory bounds. This flaw can arise in scenarios involving the secure encryption of virtualized environments, potentially leading to data corruption or unexpected behavior in the guest systems. To mitigate this vulnerability, the transfer length must be appropriately limited by the destination offset, as already enforced in related functions.

Affected Version(s)

Linux 24f41fb23a39bc2b6f190dcef35a5813a4bf183a

Linux 24f41fb23a39bc2b6f190dcef35a5813a4bf183a < 64f2449841ffc7d203183aa4c748c9c77951ecc5

Linux 24f41fb23a39bc2b6f190dcef35a5813a4bf183a < 9349b50f4b11f135fe73b56cb2c2c872d8bc71d7

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.