Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN" Revert… (CVE-2026-72239)
In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN" Revert 99cf1fb58e68 ("x86/virt/sev: Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN"). Section 8.8 of the SNP spec says: Before invoking SNP_INIT_EX with INIT_RMP set to 1, software must ensure that no CPUs contain dirty cache lines for the memory containing the RMP. Cachelines can be moved from cache to cache in a dirty state. The wbinvd_on_all_cpus() before SNP_INIT_EX flushes the caches for each CPU, but if the IPIs for WBINVD race with this dirty cacheline movement, it is possible that they may not get flushed, violating the firmware requirement. Doing wbinvd_on_all_cpus() before setting SNPEn is safer since the RMP table is not yet in use. [ Heroically bisected by Srikanth. ] [ bp: Massage commit message. ]
AI Analysis
Technical Summary
The vulnerability (CVE-2026-72239) in the Linux kernel concerns the x86/virt/sev code path where the sequence of cache flushing (WBINVD) and setting the MSR_AMD64_SYSCFG_SNP_EN register was incorrect. The original commit dropped WBINVD before setting the register, but this introduced a race condition where dirty cache lines could be moved between CPUs and not flushed properly, violating the SNP specification which requires all CPUs to have clean caches for the memory containing the RMP table before initialization. The fix reverts this commit, ensuring that the cache flush (wbinvd_on_all_cpus()) happens before enabling SNP, thus maintaining compliance with the SNP spec and preventing potential memory protection issues.
Potential Impact
If unpatched, the race condition could allow dirty cache lines to remain unflushed during SNP initialization, potentially violating firmware requirements and undermining memory protection guarantees. This could affect the security guarantees of Secure Nested Paging on AMD SEV-enabled systems, possibly leading to memory integrity issues. However, no known exploits are reported in the wild.
Mitigation Recommendations
A fix has been applied by reverting the problematic commit to ensure proper cache flushing before enabling SNP. Users should update their Linux kernel to a version that includes this revert to mitigate the vulnerability. Since this is a kernel-level fix, applying the official kernel update from the vendor or distribution is the recommended remediation. Patch status is confirmed by the revert commit; no additional mitigation steps are indicated.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN" Revert… (CVE-2026-72239)
Description
In the Linux kernel, the following vulnerability has been resolved: x86/virt/sev: Revert "Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN" Revert 99cf1fb58e68 ("x86/virt/sev: Drop WBINVD before setting MSR_AMD64_SYSCFG_SNP_EN"). Section 8.8 of the SNP spec says: Before invoking SNP_INIT_EX with INIT_RMP set to 1, software must ensure that no CPUs contain dirty cache lines for the memory containing the RMP. Cachelines can be moved from cache to cache in a dirty state. The wbinvd_on_all_cpus() before SNP_INIT_EX flushes the caches for each CPU, but if the IPIs for WBINVD race with this dirty cacheline movement, it is possible that they may not get flushed, violating the firmware requirement. Doing wbinvd_on_all_cpus() before setting SNPEn is safer since the RMP table is not yet in use. [ Heroically bisected by Srikanth. ] [ bp: Massage commit message. ]
CVSS v3.1
Score 9.3critical
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-72239) in the Linux kernel concerns the x86/virt/sev code path where the sequence of cache flushing (WBINVD) and setting the MSR_AMD64_SYSCFG_SNP_EN register was incorrect. The original commit dropped WBINVD before setting the register, but this introduced a race condition where dirty cache lines could be moved between CPUs and not flushed properly, violating the SNP specification which requires all CPUs to have clean caches for the memory containing the RMP table before initialization. The fix reverts this commit, ensuring that the cache flush (wbinvd_on_all_cpus()) happens before enabling SNP, thus maintaining compliance with the SNP spec and preventing potential memory protection issues.
Potential Impact
If unpatched, the race condition could allow dirty cache lines to remain unflushed during SNP initialization, potentially violating firmware requirements and undermining memory protection guarantees. This could affect the security guarantees of Secure Nested Paging on AMD SEV-enabled systems, possibly leading to memory integrity issues. However, no known exploits are reported in the wild.
Mitigation Recommendations
A fix has been applied by reverting the problematic commit to ensure proper cache flushing before enabling SNP. Users should update their Linux kernel to a version that includes this revert to mitigate the vulnerability. Since this is a kernel-level fix, applying the official kernel update from the vendor or distribution is the recommended remediation. Patch status is confirmed by the revert commit; no additional mitigation steps are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mh7r-v762-68jw
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-72239"]
Threat ID: 6a808b73bf8831d5394fd6cf
Added to database: 08/15/2026, 15:53:23 UTC
Last enriched: 08/15/2026, 16:44:16 UTC
Last updated: 09/30/2026, 06:54:40 UTC
Views: 54
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.