In the Linux kernel, the following vulnerability has been resolved:
crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)
Sashiko notes:
if SEV initialization fails and KVM is actively running normal VMs, could a
userspace process trigger this code path via /dev/sev ioctls (e.g.,
SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN
execution for an active VM trigger a general protection fault and crash the
host?
The SNP_COMMIT command does not require the firmware to be in any
particular state. Skip initializing it if it was previously uninitialized.
The SEV-SNP firmware specification doc 56860 does not mention SNP_COMMIT in
Table 5 as a command that is allowed in the UNINIT state, but it is in fact
allowed and a future documentation update will reflect that.