Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's KVM SEV (Secure Encrypted Virtualization) module has been addressed. The issue involved a time-of-check-to-time-of-use (TOCTOU) vulnerability when reading entries from the guest-accessible Page State Change (PSC) buffer. This vulnerability could be exploited by misbehaving guests to interfere with the processing of PSC entries, potentially leading to incorrect behavior in virtual machine management.
Exploitation of this vulnerability could allow a guest to manipulate the Page State Change processing, potentially causing errors in how the hypervisor manages virtual machine memory states.
The vulnerability could be reproduced by a guest virtual machine that misbehaves or violates the expected interaction with the Page State Change buffer. This could involve sending unexpected or malformed data that the hypervisor processes as part of the normal PSC entry handling.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched kernel can be found on the official Linux kernel website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.