E-Ink News Daily

Back to list

I found a KVM guest-to-host heap corruption bug and someone else got there first

The author discovered a heap out-of-bounds read/write vulnerability in KVM's SEV-SNP Page State Change handler, allowing malicious guests to escape their VM and corrupt host kernel heap memory. While reported to the KVM team, they were informed another researcher had reported it first; the bug was fixed in mainline commit db3f2195d293 as CVE-2026-53360.

Background

SEV-SNP (Secure Encrypted Virtualization - Secure Nested Paging) is AMD's hardware virtualization security feature that encrypts VM memory. KVM is Linux's native hypervisor. This bug affects all kernels with SNP PSC support since ~v6.10.

Source
Lobsters
Published
Aug 13, 2026 at 02:05 AM
Score
8.0 / 10