CVE-2026-63939
A critical flaw in the Linux kernel’s KVM SEV component can let an attacker overflow a kernel buffer by manipulating the GHCB scratch area length. The bug was caused by miscalculating the maximum size of the scratch area, which could corrupt memory. The issue has been fixed in a kernel update.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, specifically the KVM SEV (Secure Encrypted Virtualization) implementation used in virtualized environments.
Real-world impact
An attacker could trigger a buffer overflow in the kernel, potentially gaining arbitrary code execution or causing a denial‑of‑service on the host machine.
Why this severity
The CVSS score of 9.3 reflects that the vulnerability can be exploited locally without privileges, requires no user interaction, and can compromise confidentiality, integrity, and availability by allowing a kernel buffer overflow.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the KVM SEV patch that corrects the GHCB scratch area length calculation.
- 02Restart the system to load the updated kernel.
NVD-referenced vendor advisory
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 27, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.