CVE-2026-63937
TOCTOU in KVM SEV PSC buffer lets malicious guest induce host memory corruption or data leaks.
Is CVE-2026-63937 being exploited?
Not confirmed. CVE-2026-63937 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.17% probability of exploitation in the next 30 days.
How severe is CVE-2026-63937?
CVE-2026-63937 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63937?
Yes. A fix has been recorded for CVE-2026-63937. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63937 affect?
CVE-2026-63937 affects Linux kernel (KVM) with AMD SEV, SEV-enabled virtualization hosts, Cloud providers using KVM/SEV, Distributions' Linux kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63937?
Update host kernels to fixed versions and restrict untrusted SEV guests until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A malicious VM can race PSC buffer reads to cause inconsistent indices, enabling host memory corruption, information disclosure, or potential VM escape.
Patch when possible
- affected>= 9b54e248d2644be71cb394eb85f31ad99e023a05 and < bd232801ef1d1fd985d2d4ca3cd1d888303ca86f
- affected>= 9b54e248d2644be71cb394eb85f31ad99e023a05 and < b1dfaa6f7a957726a6800135be3659fbe4bbf2a4
- affected>= 9b54e248d2644be71cb394eb85f31ad99e023a05 and < edbbe88f83b524434974e84808d3093199d67c24
- affected>= 9b54e248d2644be71cb394eb85f31ad99e023a05 and < c8cc238093ca6c99267032f6cfe78f59389f3157
- affected6.11
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.