Linux Kernel Vulnerability in KVM with AMD SEV-SNP Technology
CVE-2026-90040

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90040?

A memory management vulnerability in the Linux kernel's KVM implementation can potentially allow improper handling of virtual machine memory access during invalid memory operations. Specifically, this issue arises when managing the Secure Encrypted Virtualization (SEV) in AMD's hardware, which necessitates the invalidation of the vCPU's control structure if the backing memory page is invalidated or removed. If these operations are mishandled, it may result in failures during memory reclaim operations, which could undermine the stability and security of guest virtual machines. Properly invalidating the Virtual Machine State Area (VMSA) is essential to prevent operational disruptions and ensure the reliability of memory accesses during runtime scenarios.

Affected Version(s)

Linux e366f92ea99e1961fbad5e2110900e9f4fcb249b < 2640cc26ed0dd1bf6ec2f6852a60e494093db3e5

Linux e366f92ea99e1961fbad5e2110900e9f4fcb249b

Linux 6.11

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.