What is CVE-2026-64285?
A vulnerability has been discovered in the Linux kernel where KVM fails to properly pin a source page for writing when populating CPUID data for an SEV SNP guest, potentially leading to memory corruption. This affects systems using guest_memfd for SNP guests. Kernel updates should be applied to affected systems.
Azərbaycanca: Linux nüvəsində, KVM SEV SNP qonağı üçün CPUID məlumatlarını əlavə edərkən mənbə səhifəsinin yazmaq üçün düzgün pin edilməməsi səbəbindən yaddaş korrupsiyasına yol aça biləcək bir zəiflik aşkarlanıb. Bu, SNP qonaqları üçün guest_memfd konfiqurasiyasına təsir edir. Təsirə məruz qalan sistemlərdə nüvə yeniləməsi tətbiq edilməlidir.
FAQ2
Which technology is affected by CVE-2026-64285?
This vulnerability affects the Linux kernel, specifically the KVM component when using guest_memfd configurations for SEV SNP guests.
What problem can arise as a result of CVE-2026-64285?
It can potentially lead to memory corruption due to the source page not being properly pinned for writing.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.