Improper control of a resource through its lifetime in Linux kernel - CVE-2026-64308
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state management in the sev ioctl handler for SNP_VLEK_LOAD when handling ioctl requests to /dev/sev without prior SNP initialization. A local user can issue a crafted ioctl request to trigger host crashes.
Exploitation requires access to the SEV device interface, and the issue can affect hosts running active virtual machines.