Skip to main content
EPSS 0.2%top 93%

Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN" Revert… (CVE-2026-72239)

0
Medium
Published: 08/17/2026 (08/17/2026, 00:00:00 UTC)
Source: GCVE Database
Product: linux-hwe-edge

Description

In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN" Revert 99cf1fb58e68 ("x86/virt/sev: Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN"). Section 8.8 of the SNP spec says: Before invoking SNP_INIT_EX with INIT_RMP set to 1, software must ensure that no CPUs contain dirty cache lines for the memory containing the RMP. Cachelines can be moved from cache to cache in a dirty state. The wbinvd_on_all_cpus() before SNP_INIT_EX flushes the caches for each CPU, but if the IPIs for WBINVD race with this dirty cacheline movement, it is possible that they may not get flushed, violating the firmware requirement. Doing wbinvd_on_all_cpus() before setting SNPEn is safer since the RMP table is not yet in use. [ Heroically bisected by Srikanth. ] [ bp: Massage commit message. ]

CVSS v3.1

Score 9.3critical

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 16:44:16 UTC

Technical Analysis

The vulnerability (CVE-2026-72239) in the Linux kernel concerns the x86/virt/sev code path where the sequence of cache flushing (WBINVD) and setting the MSR_AMD64_SYSCFG_SNP_EN register was incorrect. The original commit dropped WBINVD before setting the register, but this introduced a race condition where dirty cache lines could be moved between CPUs and not flushed properly, violating the SNP specification which requires all CPUs to have clean caches for the memory containing the RMP table before initialization. The fix reverts this commit, ensuring that the cache flush (wbinvd_on_all_cpus()) happens before enabling SNP, thus maintaining compliance with the SNP spec and preventing potential memory protection issues.

Potential Impact

If unpatched, the race condition could allow dirty cache lines to remain unflushed during SNP initialization, potentially violating firmware requirements and undermining memory protection guarantees. This could affect the security guarantees of Secure Nested Paging on AMD SEV-enabled systems, possibly leading to memory integrity issues. However, no known exploits are reported in the wild.

Mitigation Recommendations

A fix has been applied by reverting the problematic commit to ensure proper cache flushing before enabling SNP. Users should update their Linux kernel to a version that includes this revert to mitigate the vulnerability. Since this is a kernel-level fix, applying the official kernel update from the vendor or distribution is the recommended remediation. Patch status is confirmed by the revert commit; no additional mitigation steps are indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-mh7r-v762-68jw
Osv Schema Version
1.4.0
Aliases
["CVE-2026-72239"]

Threat ID: 6a808b73bf8831d5394fd6cf

Added to database: 08/15/2026, 15:53:23 UTC

Last enriched: 08/15/2026, 16:44:16 UTC

Last updated: 09/30/2026, 06:54:40 UTC

Views: 54

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses