Improper Initialization in Linux kernel - CVE-2026-64309
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the sev ioctl SNP_COMMIT handler when processing ioctl requests. A local user can invoke the SNP_COMMIT ioctl to cause a denial of service.
Exploitation requires access to /dev/sev, and the issue can crash the host by triggering a general protection fault during subsequent VMRUN execution for an active VM.