CVE-2026-80853
In the Linux kernel, the following vulnerability has been resolved:
KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts
When {de,en}crypting memory of an SEV or SEV-ES guest on an SNP-enabled host via a temporary buffer, allocate a full 4KiB page for the buffer to ensure the page containing the buffer is wholly owned by KVM, i.e. won't be concurrently allocated and accessed by other kernel code while KVM is using the buffer to {de,en}crypt memory.
Leer descripción completaMostrar menos
On SNP-enabled platforms, when sending SEV/SEV-ES commands that trigger firmware writes to memory, the to-be-written page(s) must be (temporarily) assigned to Firmware (as required by the SNP architecture, to guard against using such commands as gadgets to attack SNP guests). See snp_map_cmd_buf_desc() and friends.
Unfortunately, transferring ownership of a page to Firmware makes the page inaccessible to software, and thus writes generate RMP #PF violations. If KVM uses a sub-page allocation for its temporary buffer, some other actor in the kernel can allocate and use the other portions of the page, and thus trigger unexpected (and seemingly spurious) RMP #PF violations due to software attempting to access a Firmware-owned page.
Detalles técnicos trazas, registros y código del informe original
BUG: unable to handle page fault for address: ffff906ae30f0300 #PF: supervisor write access in kernel mode #PF: error_code(0x80000003) - RMP violation PGD 6b1b80d067 P4D 6b1b80d067 PUD 100231e2063 PMD 10055a88063 PTE 80000100630f0163 SEV-SNP: PFN 0x100630f0 unassigned, dumping non-zero entries in 2M PFN region: [0x10063000 - 0x10063200] Oops: Oops: 0003 [#1] SMP CPU: 70 UID: 0 PID: 10658 Comm: svw_WaiterThrea Tainted: G U W O 7.1.0-smp--c22293789940-seanjc-next #1 PREEMPTLAZY Tainted: [U]=USER, [W]=WARN, [O]=OOT_MODULE Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.86.0-102 01/25/2026 RIP: 0010:memset+0xf/0x20 Call Trace: <TASK> __kvmalloc_node_noprof+0x2a4/0x710 do_getxattr+0x4e/0x130 path_getxattrat+0x125/0x1b0 do_syscall_64+0x10a/0x480 entry_SYSCALL_64_after_hwframe+0x4b/0x53 RIP: 0033:0x7f3a22cb6daa </TASK> Modules linked in: kvm_amd kvm irqbypass vfat fat ccp k10temp sha3 libsha3 i2c_piix4 gq(O) cdc_acm xhci_pci xhci_hcd gsmi: Log Shutdown Reason 0x03 CR2: ffff906ae30f0300 ---[ end trace 0000000000000000 ]--- RIP: 0010:memset+0xf/0x20 Kernel panic - not syncing: Fatal exception Kernel Offset: 0x39e00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff) gsmi: Log Shutdown Reason 0x02
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80853",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4c735bf1bc22fd6ee66ab4bffe1d7599c3964781",
"lessThan": "97f6402f5950ca3450541287c4b3664f3acda976",
"versionType": "git"
},
{
"status": "affected",
"version": "4c735bf1bc22fd6ee66ab4bffe1d7599c3964781",
"lessThan": "a33c40b93ccf5177e042253807d40e0b92e7f206",
"versionType": "git"
}
],
"programFiles": [
"arch/x86/kvm/svm/sev.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "7.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/x86/kvm/svm/sev.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-04T16:18:14.233",
"references": [
{
"url": "https://git.kernel.org/stable/c/97f6402f5950ca3450541287c4b3664f3acda976",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a33c40b93ccf5177e042253807d40e0b92e7f206",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts\n\nWhen {de,en}crypting memory of an SEV or SEV-ES guest on an SNP-enabled\nhost via a temporary buffer, allocate a full 4KiB page for the buffer to\nensure the page containing the buffer is wholly owned by KVM, i.e. won't\nbe concurrently allocated and accessed by other kernel code while KVM is\nusing the buffer to {de,en}crypt memory. On SNP-enabled platforms, when\nsending SEV/SEV-ES commands that trigger firmware writes to memory, the\nto-be-written page(s) must be (temporarily) assigned to Firmware (as\nrequired by the SNP architecture, to guard against using such commands as\ngadgets to attack SNP guests). See snp_map_cmd_buf_desc() and friends.\n\nUnfortunately, transferring ownership of a page to Firmware makes the page\ninaccessible to software, and thus writes generate RMP #PF violations. If\nKVM uses a sub-page allocation for its temporary buffer, some other actor\nin the kernel can allocate and use the other portions of the page, and thus\ntrigger unexpected (and seemingly spurious) RMP #PF violations due to\nsoftware attempting to access a Firmware-owned page.\n\n BUG: unable to handle page fault for address: ffff906ae30f0300\n #PF: supervisor write access in kernel mode\n #PF: error_code(0x80000003) - RMP violation\n PGD 6b1b80d067 P4D 6b1b80d067 PUD 100231e2063 PMD 10055a88063 PTE 80000100630f0163\n SEV-SNP: PFN 0x100630f0 unassigned, dumping non-zero entries in 2M PFN region: [0x10063000 - 0x10063200]\n Oops: Oops: 0003 [#1] SMP\n CPU: 70 UID: 0 PID: 10658 Comm: svw_WaiterThrea Tainted: G U W O 7.1.0-smp--c22293789940-seanjc-next #1 PREEMPTLAZY\n Tainted: [U]=USER, [W]=WARN, [O]=OOT_MODULE\n Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.86.0-102 01/25/2026\n RIP: 0010:memset+0xf/0x20\n Call Trace:\n <TASK>\n __kvmalloc_node_noprof+0x2a4/0x710\n do_getxattr+0x4e/0x130\n path_getxattrat+0x125/0x1b0\n do_syscall_64+0x10a/0x480\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n RIP: 0033:0x7f3a22cb6daa\n </TASK>\n Modules linked in: kvm_amd kvm irqbypass vfat fat ccp k10temp sha3 libsha3 i2c_piix4 gq(O) cdc_acm xhci_pci xhci_hcd\n gsmi: Log Shutdown Reason 0x03\n CR2: ffff906ae30f0300\n ---[ end trace 0000000000000000 ]---\n RIP: 0010:memset+0xf/0x20\n Kernel panic - not syncing: Fatal exception\n Kernel Offset: 0x39e00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)\n gsmi: Log Shutdown Reason 0x02"
}
],
"lastModified": "2026-09-04T16:18:14.233",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}