{"api_version":"1","generated_at":"2026-07-23T21:03:40+00:00","cve":"CVE-2026-63940","urls":{"html":"https://cve.report/CVE-2026-63940","api":"https://cve.report/api/cve/CVE-2026-63940.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-63940","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-63940"},"summary":{"title":"KVM: SEV: Ignore Port I/O requests of length '0'","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Ignore Port I/O requests of length '0'\n\nExplicitly ignore Port I/O requests of length '0' (or count '0'), so that\nsetting up the software scratch area (and other code) doesn't have to\nworry about underflowing the length, and to allow for WARNing on trying\nto configure the scratch area with len==0.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-19 16:17:12","updated_at":"2026-07-20 15:16:57"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.3","severity":"CRITICAL","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.3","severity":"CRITICAL","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":9.3,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/3b6035bc6bff20e89752ce4358bc4c9a9d5883f2","name":"https://git.kernel.org/stable/c/3b6035bc6bff20e89752ce4358bc4c9a9d5883f2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3988bd2723de407ae90fa7a6f6029b4e60238c58","name":"https://git.kernel.org/stable/c/3988bd2723de407ae90fa7a6f6029b4e60238c58","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2254972d4d69e279ba4e87bf0968eb08ad0d3c92","name":"https://git.kernel.org/stable/c/2254972d4d69e279ba4e87bf0968eb08ad0d3c92","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c30cde934c7813b4e3069765dac64ce3d31e34f2","name":"https://git.kernel.org/stable/c/c30cde934c7813b4e3069765dac64ce3d31e34f2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-63940","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63940","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 291bd20d5d88814a73d43b55b9428feab2f28094 3b6035bc6bff20e89752ce4358bc4c9a9d5883f2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 291bd20d5d88814a73d43b55b9428feab2f28094 2254972d4d69e279ba4e87bf0968eb08ad0d3c92 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 291bd20d5d88814a73d43b55b9428feab2f28094 c30cde934c7813b4e3069765dac64ce3d31e34f2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 291bd20d5d88814a73d43b55b9428feab2f28094 3988bd2723de407ae90fa7a6f6029b4e60238c58 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.11","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.95 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.35 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0.12 7.0.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"63940","cve":"CVE-2026-63940","epss":"0.002000000","percentile":"0.100220000","score_date":"2026-07-20","updated_at":"2026-07-21 00:13:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["arch/x86/kvm/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"3b6035bc6bff20e89752ce4358bc4c9a9d5883f2","status":"affected","version":"291bd20d5d88814a73d43b55b9428feab2f28094","versionType":"git"},{"lessThan":"2254972d4d69e279ba4e87bf0968eb08ad0d3c92","status":"affected","version":"291bd20d5d88814a73d43b55b9428feab2f28094","versionType":"git"},{"lessThan":"c30cde934c7813b4e3069765dac64ce3d31e34f2","status":"affected","version":"291bd20d5d88814a73d43b55b9428feab2f28094","versionType":"git"},{"lessThan":"3988bd2723de407ae90fa7a6f6029b4e60238c58","status":"affected","version":"291bd20d5d88814a73d43b55b9428feab2f28094","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["arch/x86/kvm/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.11"},{"lessThan":"5.11","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.95","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.35","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.12","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.95","versionStartIncluding":"5.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.35","versionStartIncluding":"5.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.12","versionStartIncluding":"5.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1","versionStartIncluding":"5.11","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Ignore Port I/O requests of length '0'\n\nExplicitly ignore Port I/O requests of length '0' (or count '0'), so that\nsetting up the software scratch area (and other code) doesn't have to\nworry about underflowing the length, and to allow for WARNing on trying\nto configure the scratch area with len==0."}],"metrics":[{"cvssV3_1":{"baseScore":9.3,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"providerMetadata":{"dateUpdated":"2026-07-20T13:41:42.039Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/3b6035bc6bff20e89752ce4358bc4c9a9d5883f2"},{"url":"https://git.kernel.org/stable/c/2254972d4d69e279ba4e87bf0968eb08ad0d3c92"},{"url":"https://git.kernel.org/stable/c/c30cde934c7813b4e3069765dac64ce3d31e34f2"},{"url":"https://git.kernel.org/stable/c/3988bd2723de407ae90fa7a6f6029b4e60238c58"}],"title":"KVM: SEV: Ignore Port I/O requests of length '0'","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-63940","datePublished":"2026-07-19T14:55:36.408Z","dateReserved":"2026-07-19T07:54:57.022Z","dateUpdated":"2026-07-20T13:41:42.039Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-19 16:17:12","lastModifiedDate":"2026-07-20 15:16:57","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"63940","Ordinal":"1","Title":"KVM: SEV: Ignore Port I/O requests of length '0'","CVE":"CVE-2026-63940","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"63940","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Ignore Port I/O requests of length '0'\n\nExplicitly ignore Port I/O requests of length '0' (or count '0'), so that\nsetting up the software scratch area (and other code) doesn't have to\nworry about underflowing the length, and to allow for WARNing on trying\nto configure the scratch area with len==0.","Type":"Description","Title":"KVM: SEV: Ignore Port I/O requests of length '0'"}]}}}