CVE-2026-64309 PUBLISHED

crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)

Sashiko notes:

if SEV initialization fails and KVM is actively running normal VMs, could a userspace process trigger this code path via /dev/sev ioctls (e.g., SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN execution for an active VM trigger a general protection fault and crash the host?

The SNP_COMMIT command does not require the firmware to be in any particular state. Skip initializing it if it was previously uninitialized.

The SEV-SNP firmware specification doc 56860 does not mention SNP_COMMIT in Table 5 as a command that is allowed in the UNINIT state, but it is in fact allowed and a future documentation update will reflect that.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1c3506ea8599a3ad1b9aae5cbd573134f8d18db7 to 74768f73854d647a6462f252dc8782ab8a835211 (excl.)
  • affected from ceac7fb89e8da465aec3ac3c20477f912f5c3a6c to 7a361c74bb12f3398c388905f1d325be642cd36e (excl.)
  • affected from ceac7fb89e8da465aec3ac3c20477f912f5c3a6c to 67ed191b4c8bdf432a3f32d1eb302880b4795cd1 (excl.)
  • affected from ceac7fb89e8da465aec3ac3c20477f912f5c3a6c to 5a1364da2f04217a36e2fdfa2db4ee025b383a20 (excl.)
  • affected from 6.12.75 to 6.12.96 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.16 is affected
  • unaffected from 0 to 6.16 (excl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References