Database/Firmware, BMC & network fabric

Linux KVM/SVM - source vCPU selection in SEV-ES intra-host migration: KVM fetched source vCPUs from the wrong VM
Impact
KVM fetched source vCPUs from the wrong VM during SEV-ES intra-host migration. Operating on the wrong VM's vCPU structures during a confidential-VM migration is a cross-VM state confusion bug - exactly the failure class you do not want on the code path that moves encrypted guest state around.
Who can reach it
Through the KVM migration ioctl path, from the VMM.
What to do
Fixed in the Linux kernel. Take the distro kernel update (RHEL/Rocky, Ubuntu, SLES) and reboot the host - no firmware, VBIOS or AGESA step. On a GPU fleet this is a cordon, drain and rolling reboot; plan it as normal kernel maintenance.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.