{"api_version":"1","generated_at":"2026-07-23T23:18:05+00:00","cve":"CVE-2026-63938","urls":{"html":"https://cve.report/CVE-2026-63938","api":"https://cve.report/api/cve/CVE-2026-63938.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-63938","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-63938"},"summary":{"title":"KVM: SEV: Check PSC request indices against the actual size of the buffer","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Check PSC request indices against the actual size of the buffer\n\nWhen processing Page State Change (PSC) requests, validate the PSC buffer\nagainst the effective size of the scratch area, which could be less than\nthe maximum size if the guest provided a pointer that isn't exactly at the\nstart of the GHCB shared buffer.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-19 16:17:12","updated_at":"2026-07-20 15:16:57"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.3","severity":"CRITICAL","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.3","severity":"CRITICAL","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":9.3,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/5198f70c09a5f6e9e5f5a0a2c6b388f24294b176","name":"https://git.kernel.org/stable/c/5198f70c09a5f6e9e5f5a0a2c6b388f24294b176","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/505a3b94535583e4265360e2621734e355ef263d","name":"https://git.kernel.org/stable/c/505a3b94535583e4265360e2621734e355ef263d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/75c8d1d7291268b479794fba5808971dc2f5eaf3","name":"https://git.kernel.org/stable/c/75c8d1d7291268b479794fba5808971dc2f5eaf3","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/121d88de56bc5c0ba0ce2f6381af67f948a7e7c1","name":"https://git.kernel.org/stable/c/121d88de56bc5c0ba0ce2f6381af67f948a7e7c1","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-63938","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63938","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9b54e248d2644be71cb394eb85f31ad99e023a05 5198f70c09a5f6e9e5f5a0a2c6b388f24294b176 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9b54e248d2644be71cb394eb85f31ad99e023a05 75c8d1d7291268b479794fba5808971dc2f5eaf3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9b54e248d2644be71cb394eb85f31ad99e023a05 505a3b94535583e4265360e2621734e355ef263d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9b54e248d2644be71cb394eb85f31ad99e023a05 121d88de56bc5c0ba0ce2f6381af67f948a7e7c1 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.11","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.93 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.35 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0.12 7.0.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"63938","cve":"CVE-2026-63938","epss":"0.002000000","percentile":"0.100180000","score_date":"2026-07-20","updated_at":"2026-07-21 00:13:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["arch/x86/kvm/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"5198f70c09a5f6e9e5f5a0a2c6b388f24294b176","status":"affected","version":"9b54e248d2644be71cb394eb85f31ad99e023a05","versionType":"git"},{"lessThan":"75c8d1d7291268b479794fba5808971dc2f5eaf3","status":"affected","version":"9b54e248d2644be71cb394eb85f31ad99e023a05","versionType":"git"},{"lessThan":"505a3b94535583e4265360e2621734e355ef263d","status":"affected","version":"9b54e248d2644be71cb394eb85f31ad99e023a05","versionType":"git"},{"lessThan":"121d88de56bc5c0ba0ce2f6381af67f948a7e7c1","status":"affected","version":"9b54e248d2644be71cb394eb85f31ad99e023a05","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["arch/x86/kvm/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.11"},{"lessThan":"6.11","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.93","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.35","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.12","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.93","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.35","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.12","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1","versionStartIncluding":"6.11","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Check PSC request indices against the actual size of the buffer\n\nWhen processing Page State Change (PSC) requests, validate the PSC buffer\nagainst the effective size of the scratch area, which could be less than\nthe maximum size if the guest provided a pointer that isn't exactly at the\nstart of the GHCB shared buffer."}],"metrics":[{"cvssV3_1":{"baseScore":9.3,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"providerMetadata":{"dateUpdated":"2026-07-20T13:41:40.069Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/5198f70c09a5f6e9e5f5a0a2c6b388f24294b176"},{"url":"https://git.kernel.org/stable/c/75c8d1d7291268b479794fba5808971dc2f5eaf3"},{"url":"https://git.kernel.org/stable/c/505a3b94535583e4265360e2621734e355ef263d"},{"url":"https://git.kernel.org/stable/c/121d88de56bc5c0ba0ce2f6381af67f948a7e7c1"}],"title":"KVM: SEV: Check PSC request indices against the actual size of the buffer","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-63938","datePublished":"2026-07-19T14:55:35.168Z","dateReserved":"2026-07-19T07:54:57.022Z","dateUpdated":"2026-07-20T13:41:40.069Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-19 16:17:12","lastModifiedDate":"2026-07-20 15:16:57","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"63938","Ordinal":"1","Title":"KVM: SEV: Check PSC request indices against the actual size of t","CVE":"CVE-2026-63938","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"63938","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Check PSC request indices against the actual size of the buffer\n\nWhen processing Page State Change (PSC) requests, validate the PSC buffer\nagainst the effective size of the scratch area, which could be less than\nthe maximum size if the guest provided a pointer that isn't exactly at the\nstart of the GHCB shared buffer.","Type":"Description","Title":"KVM: SEV: Check PSC request indices against the actual size of t"}]}}}