Improper control of a resource through its lifetime in Linux kernel - CVE-2026-64104
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of pages left in an unknown encryption state in drivers/virt/coco/sev-guest/sev-guest.c when handling extended report requests and memory encryption state transitions. A local user can trigger failures in set_memory_encrypted() or set_memory_decrypted() to cause a denial of service.
The issue affects pages that may remain in an unencrypted or otherwise unknown state and therefore cannot be safely returned for general reuse.