{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.177-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.95-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.3-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path  In sev_dbg_crypt(), the per-iteration transfer length is bounded by the source page offset (PAGE_SIZE - s_off) but not by the destination page offset (PAGE_SIZE - d_off).  When d_off \u003e s_off, the encrypt path (__sev_dbg_encrypt_user) performs a read-modify-write using a single-page intermediate buffer (dst_tpage):    1. __sev_dbg_decrypt() expands the size to round_up(len + (d_off \u0026 15), 16)      before issuing the PSP command.  If len + (d_off \u0026 15) \u003e PAGE_SIZE,      the PSP writes beyond the end of the 4096-byte dst_tpage allocation.    2. The subsequent memcpy()/copy_from_user() into      page_address(dst_tpage) + (d_off \u0026 15) of 'len' bytes overflows      by up to 15 bytes under the same condition.  Trigger example: s_off = 0, d_off = 1, debug.len = PAGE_SIZE - the PSP is instructed to write round_up(4097, 16) = 4112 bytes to a 4096-byte buffer.  Fix by also bounding len by (PAGE_SIZE - d_off), the same check that sev_send_update_data() already performs for its single-page guest region.   ==================================================================  BUG: KASAN: slab-use-after-free in sev_dbg_crypt+0x993/0xd10 [kvm_amd]  Write of size 4095 at addr ff110062293bb009 by task sev_dbg_test/228214   CPU: 96 UID: 0 PID: 228214 Comm: sev_dbg_test Tainted: G     U  W           7.0.0-smp--5ce9b0c48211-dbg #156 PREEMPTLAZY  Tainted: [U]=USER, [W]=WARN  Hardware name: Google Astoria/astoria, BIOS 0.20250817.1-0 08/25/2025  Call Trace:   \u003cTASK\u003e   dump_stack_lvl+0x54/0x70   print_report+0xbc/0x260   kasan_report+0xa2/0xd0   kasan_check_range+0x25f/0x2c0   __asan_memcpy+0x40/0x70   sev_dbg_crypt+0x993/0xd10 [kvm_amd]   sev_mem_enc_ioctl+0x33c/0x450 [kvm_amd]   kvm_vm_ioctl+0x65d/0x6d0 [kvm]   __se_sys_ioctl+0xb2/0x100   do_syscall_64+0xe8/0x870   entry_SYSCALL_64_after_hwframe+0x4b/0x53   \u003c/TASK\u003e   The buggy address belongs to the physical page:  page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x7fe72b6a0 pfn:0x62293bb  memcg:ff11000112827d82  flags: 0x1400000000000000(node=1|zone=1)  raw: 1400000000000000 0000000000000000 dead000000000122 0000000000000000  raw: 00000007fe72b6a0 0000000000000000 00000001ffffffff ff11000112827d82  page dumped because: kasan: bad access detected   Memory state around the buggy address:   ff110062293bbf00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ff110062293bbf80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  \u003eff110062293bc000: fa fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc                     ^   ff110062293bc080: fa fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc   ff110062293bc100: fa fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc  ==================================================================  Disabling lock debugging due to kernel taint  [sean: add sample KASAN splat, Fixes, and stable@]",
  "id": "DEBIAN-CVE-2026-63794",
  "modified": "2026-09-14T16:47:28.694364389Z",
  "published": "2026-07-19T12:16:51.757Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-63794"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-63794"
  ]
}