CVE-2026-63938

Source
https://cve.org/CVERecord?id=CVE-2026-63938
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63938.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63938
Downstream
Published
2026-07-19T14:55:35.168Z
Modified
2026-07-21T03:47:39.216636611Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
KVM: SEV: Check PSC request indices against the actual size of the buffer
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: SEV: Check PSC request indices against the actual size of the buffer

When processing Page State Change (PSC) requests, validate the PSC buffer against the effective size of the scratch area, which could be less than the maximum size if the guest provided a pointer that isn't exactly at the start of the GHCB shared buffer.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63938.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9b54e248d2644be71cb394eb85f31ad99e023a05
Fixed
5198f70c09a5f6e9e5f5a0a2c6b388f24294b176
Fixed
75c8d1d7291268b479794fba5808971dc2f5eaf3
Fixed
505a3b94535583e4265360e2621734e355ef263d
Fixed
121d88de56bc5c0ba0ce2f6381af67f948a7e7c1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63938.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63938.json"