GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux KVM/SVM - missing sev_decommission in sev_receive_start: KVM failed to DECOMMISSION the current SEV context

CVE-2021-47389Kernel, userspace & hypervisorcurated

Impact

KVM failed to DECOMMISSION the current SEV context when binding an ASID fails after RECEIVE_START. The firmware-side SEV context is left allocated with nothing owning it, exhausting the limited pool of SEV contexts the platform supports. Repeat the failure enough times and the host can no longer launch confidential VMs at all - a resource-exhaustion denial of service against your confidential-computing capacity, reachable through the guest-import path.

Who can reach it

Through the SEV guest receive/import path - so a tenant or control-plane action that fails repeatedly, deliberately or otherwise.

What to do

Fixed in the Linux kernel. Distro kernel update plus a host reboot. Note that recovering exhausted SEV contexts on an unpatched host generally means an SNP platform shutdown/init cycle, which requires draining every confidential guest anyway.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.