Impact
The vulnerability arises from a flaw in the Linux kernel’s handling of SEV‑SNP g‑memory page invalidation. If a guest memory page backing a VMSA is removed or modified, the kernel fails to invalidate the vCPU’s control.vmsa_pa entry. The kernel then attempts to update the RMP entry but receives a failure, causing a page fault and potential kernel crash or reboot. This flaw can lead to service disruption but does not provide direct arbitrary code execution or data disclosure to an attacker.
Affected Systems
All Linux systems utilizing the Linux kernel with KVM virtualisation, specifically those that enable SEV‑SNP on AMD processors. The flaw is present in any kernel version that has not yet applied the patch referenced in the provided commits.
Risk and Exploitability
The CVSS score for this vulnerability is not supplied, but the EPSS indicates that the probability of exploitation is very low (less than 1%). The flaw is not listed in CISA’s KEV catalog. Attackers would need control over a guest VM that can punch holes in the underlying huge page backing a VMSA, making the attack scenario limited to trusted or malicious guests in a virtualised environment. Given the nature of the bug, the impact is primarily a denial of service that could be mitigated by updating to a patched kernel version.
OpenCVE Enrichment