CVE-2026-63940
A critical flaw in the Linux kernel’s KVM SEV implementation could let a local attacker send port‑I/O requests of length zero, potentially causing a crash or other erratic behavior. The issue has been fixed by making the kernel ignore such requests, preventing underflow errors. The vulnerability is now patched in recent kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users running KVM with Secure Encrypted Virtualization (SEV) who have not yet updated to a kernel version that includes the fix. This typically includes system administrators and developers managing virtualized environments.
Real-world impact
A local attacker could trigger a denial‑of‑service or cause the system to behave unpredictably, potentially compromising system integrity or availability.
Why this severity
The CVSS score of 9.3 reflects a local, privilege‑less attack that can compromise confidentiality, integrity, and availability, making it a critical vulnerability.
What to do about it
- 01Update the Linux kernel to a version that includes the fix for CVE-2026-63940.
NVD description indicates the issue has been resolved.
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 27, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.