CVE-2026-63940

Source
https://cve.org/CVERecord?id=CVE-2026-63940
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63940.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63940
Downstream
Published
2026-07-19T14:55:36.408Z
Modified
2026-07-21T03:46:59.788823383Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
KVM: SEV: Ignore Port I/O requests of length '0'
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: SEV: Ignore Port I/O requests of length '0'

Explicitly ignore Port I/O requests of length '0' (or count '0'), so that setting up the software scratch area (and other code) doesn't have to worry about underflowing the length, and to allow for WARNing on trying to configure the scratch area with len==0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63940.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
291bd20d5d88814a73d43b55b9428feab2f28094
Fixed
3b6035bc6bff20e89752ce4358bc4c9a9d5883f2
Fixed
2254972d4d69e279ba4e87bf0968eb08ad0d3c92
Fixed
c30cde934c7813b4e3069765dac64ce3d31e34f2
Fixed
3988bd2723de407ae90fa7a6f6029b4e60238c58

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63940.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
6.12.95
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63940.json"