CVE-2026-72286: KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs

Published Aug 15, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs

The intra-host migration/mirroring feature is not fully implemented for SEV-SNP VMs. The proper migration requires additional SNP-specific state such as guestreqmutex, guestreqbuf, and guestrespbuf to be transferred or initialized on the destination.

The SNP VM mirroring requires vmsa features to be copied as well otherwise ASID would be bound to SNP range while VM is detected as a SEV VM.

Reject SNP source VMs in migration/mirroring until proper SNP state transfer is implemented.

[sean: let lines poke past 80 chars, tag for stable]

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Reject SEV-SNP source VMs from intra-host migration/mirroring until proper SEV-SNP state (e.g., vmsa features and SNP-specific state such as guest_req_mutex, guest_req_buf, and guest_resp_buf) is correctly transferred/initialized on the destination.

    KVM (Linux kernel) SEV-SNP intra-host migration/mirroring for SEV-SNP VMs = reject SNP source VMs

Event History

Aug 15, 2026
CVE Published
via MITRE·05:55 AM
Data Sourced
via MITRE·05:55 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203