Linux Kernel KVM SEV Port I/O Request Length Zero Vulnerability

Vulnerability

A vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) SEV (Secure Encrypted Virtualization) module has been addressed. This vulnerability involved Port I/O requests with a length of zero, which could cause issues when setting up the software scratch area. The kernel now explicitly ignores such requests, preventing potential underflows and allowing for warnings when the scratch area is configured with a length of zero.

Impact

The vulnerability could lead to improper handling of Port I/O requests, potentially causing underflows that disrupt the configuration of the software scratch area.

Reproduction

The vulnerability can be reproduced by sending Port I/O requests with a length of zero to the KVM SEV module. This can be done by configuring a virtual machine to use SEV and then issuing I/O requests that intentionally have a zero length. The kernel's previous handling of these requests could lead to underflows, which are now prevented by the patch.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. The patch is included in the official Linux stable releases.

Added: Jul 19, 2026, 7:47 PM
Updated: Jul 19, 2026, 7:47 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.3
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.