LiveActive security incident?Get immediate response
CVE Record

CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed When retrieving the PEK CSR, don't attempt to copy the blob to userspace if the firmware command failed. If the failure was due to an invalid length, i.e. the userspace buffer+length was too small, copying the number of bytes _firmware_ requires will overflow the kernel-allocated buffer and leak data to userspace. BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline] BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline] BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26 Read of size 2084 at addr ffff898144612e20 by task syz.9.219/21405 CPU: 14 UID: 0 PID: 21405 Comm: syz.9.219 Tainted: G U O 7.0.0-smp-DEV #28 PREEMPTLAZY Tainted: [U]=USER, [O]=OOT_MODULE Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.62.0-0 11/19/2025 Call Trace: <TASK> dump_stack_lvl+0xc5/0x110 ../lib/dump_stack.c:120 print_address_description ../mm/kasan/report.c:378 [inline] print_report+0xbc/0x260 ../mm/kasan/report.c:482 kasan_report+0xa2/0xe0 ../mm/kasan/report.c:595 check_region_inline ../mm/kasan/generic.c:-1 [inline] kasan_check_range+0x264/0x2c0 ../mm/kasan/generic.c:200 instrument_copy_to_user ../include/linux/instrumented.h:129 [inline] _inline_copy_to_user ../include/linux/uaccess.h:205 [inline] _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26 copy_to_user ../include/linux/uaccess.h:236 [inline] sev_ioctl_do_pek_csr+0x31f/0x590 ../drivers/crypto/ccp/sev-dev.c:1872 sev_ioctl+0x3a4/0x490 ../drivers/crypto/ccp/sev-dev.c:2562 vfs_ioctl ../fs/ioctl.c:51 [inline] __do_sys_ioctl ../fs/ioctl.c:597 [inline] __se_sys_ioctl+0x11d/0x1b0 ../fs/ioctl.c:583 do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xe0/0x800 ../arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e </TASK> WARN if the driver says the command succeeded, but the firmware error code says otherwise, as __sev_do_cmd_locked() is expected to return -EIO on any firwmware error.

HighCVSS 7.1Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A local user or process with access to the Linux SEV interface may receive kernel memory that should not be disclosed. The flaw occurs after a firmware request fails and can expose sensitive data; the supplied CVSS also indicates possible system disruption. It is not remotely exploitable under the supplied vector.

Executive priority

Treat as high priority on shared or multi-tenant hosts exposing SEV functionality to less-trusted workloads because kernel-memory disclosure can cross security boundaries. Use normal patch cadence for systems demonstrably lacking the relevant driver, hardware, or interface access, while documenting that determination.

Technical view

The CCP/SEV driver continues copying a PEK certificate-signing request after a failed PSP firmware command. When failure reflects an undersized userspace buffer, the firmware-required length can exceed the kernel allocation, causing a slab out-of-bounds read during copy_to_user and leaking adjacent kernel memory.

Likely exposure

Exposure is most likely on affected Linux systems using the CCP/SEV driver where less-trusted local processes can access the relevant SEV ioctl. Downstream distribution exposure depends on backports and device permissions. The bundle does not identify affected distributions, appliances, or cloud services.

Exploitation context

The supplied CVSS is 7.1 with local access, low privileges, low complexity, and no user interaction. The bundle reports no KEV listing or active exploitation. Its KASAN reproducer ran as UID 0, so the practical permissions required should be confirmed despite the PR:L rating.

Researcher notes

The documented primitive is a kernel slab out-of-bounds read, not a write. The description clearly supports information disclosure; the supplied CVSS additionally claims high availability impact without describing the disruption mechanism. No public exploitation evidence, leaked-data characterization, or downstream backport matrix is included.

Mitigation direction

  • Install a vendor kernel update containing the applicable referenced stable fix or an equivalent backport.
  • Confirm remediation through the Linux distribution or appliance vendor's security guidance.
  • Restrict SEV device access to trusted workloads and administrators until remediation is verified.
  • Prioritize shared systems where less-trusted local workloads can reach the SEV interface.

Validation and detection

  • Inventory running kernel versions on systems using AMD PSP/SEV functionality.
  • Determine whether the CCP/SEV driver and relevant hardware interface are present and enabled.
  • Review permissions controlling which users and workloads can access the SEV device interface.
  • Verify the installed kernel contains a referenced fix or vendor-equivalent backport.
  • After updating, confirm the replacement kernel is running across all affected hosts.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2026-31699 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.1 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
0ADP providers
9Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.1CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H1.85.2Linux

Vulnerability scoring details

Base CVSS 3.1 score

7.1High
CVSS 3.1 vector shape for CVE-2026-31699Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxe799035609e1526761aa2f896a974b233d04d36d, e799035609e1526761aa2f896a974b233d04d36d, e799035609e1526761aa2f896a974b233d04d36d, e799035609e1526761aa2f896a974b233d04d36d, e799035609e1526761aa2f896a974b233d04d36d, e799035609e1526761aa2f896a974b233d04d36d, e799035609e1526761aa2f896a974b233d04d36d, e799035609e1526761aa2f896a974b233d04d36dunaffected
LinuxLinux4.16, 0, 5.10.258, 5.15.209, 6.1.175, 6.6.136, 6.12.84, 6.18.25, 7.0.2, 7.1affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.