CVE-2023-53996
A critical flaw in the Linux kernel’s SEV (Secure Encrypted Virtualization) handling could corrupt memory during live migration. The bug caused pages to be incorrectly marked as decrypted when addresses were not page‑aligned, leading to data corruption. The issue has been fixed in newer kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, especially systems that use Intel’s SEV feature for encrypted virtual machines.
Real-world impact
An attacker could cause data corruption during live migration of virtual machines, potentially leading to loss of data or system instability.
Why this severity
The CVSS score of 9.3 reflects that the flaw is local, requires no privileges, and can completely compromise confidentiality, integrity, and availability by corrupting memory during live migration.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for CVE-2023-53996.
- 02Restart the system to load the new kernel.
NVD description indicates the issue has been resolved.
Timeline
- Dec 24, 2025 · Dec 24, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.