THREAT OPS › Threat News › [NVD] CVE-2026-64307 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved:
crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)
Sashiko notes:
> if SEV initialization fails and KVM is actively running normal VMs, could a
> userspace process trigger this code path via /dev/sev io
[NVD] CVE-2026-64307 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) Sashiko notes: > if SEV initialization fails and KVM is actively running normal VMs, could a > userspace process trigger this code path via /dev/sev io
CVE-2026-64307 CVSS: 5.5 MEDIUM Published: 2026-07-25T10:17:11.800
In the Linux kernel, the following vulnerability has been resolved:
crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)
Sashiko notes:
> if SEV initialization fails and KVM is actively running normal VMs, could a > userspace process trigger this code path via /dev/sev ioctls (e.g., > SEV_PDH_GEN) and zero out MSR_VM_HSAVE
Indicators of compromise
- CVE-2026-64307cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64307