CVE-2026-64309

Source
https://cve.org/CVERecord?id=CVE-2026-64309
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64309.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64309
Downstream
Published
2026-07-25T08:49:42.035Z
Modified
2026-07-27T04:03:21.203659255Z
Summary
crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)

Sashiko notes:

if SEV initialization fails and KVM is actively running normal VMs, could a userspace process trigger this code path via /dev/sev ioctls (e.g., SEVPDHGEN) and zero out MSRVMHSAVE_PA globally? Would the next VMRUN execution for an active VM trigger a general protection fault and crash the host?

The SNP_COMMIT command does not require the firmware to be in any particular state. Skip initializing it if it was previously uninitialized.

The SEV-SNP firmware specification doc 56860 does not mention SNP_COMMIT in Table 5 as a command that is allowed in the UNINIT state, but it is in fact allowed and a future documentation update will reflect that.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64309.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1c3506ea8599a3ad1b9aae5cbd573134f8d18db7
Fixed
74768f73854d647a6462f252dc8782ab8a835211
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ceac7fb89e8da465aec3ac3c20477f912f5c3a6c
Fixed
7a361c74bb12f3398c388905f1d325be642cd36e
Fixed
67ed191b4c8bdf432a3f32d1eb302880b4795cd1
Fixed
5a1364da2f04217a36e2fdfa2db4ee025b383a20
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.12.75
Fixed
6.12.96

Affected versions

v6.*
v6.12.75
v6.12.76
v6.12.77
v6.12.78
v6.12.79
v6.12.80
v6.12.81
v6.12.82
v6.12.83
v6.12.84
v6.12.85
v6.12.86
v6.12.87
v6.12.88
v6.12.89
v6.12.90
v6.12.91
v6.12.92
v6.12.93
v6.12.94
v6.12.95

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64309.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64309.json"