Database/Firmware, BMC & network fabric

Linux KVM/SEV - vCPU locking when synchronizing VMSAs for SNP launch finish: KVM did not lock all vCPUs
Impact
KVM did not lock all vCPUs while synchronising and encrypting VMSAs at SNP launch finish, so vCPU state could change underneath the encryption step. The VMSA is what the launch measurement covers; if it can move while being measured, the attestation you hand the tenant does not necessarily describe the VM that actually ran.
Who can reach it
Through the KVM SNP launch path, from the VMM process.
What to do
Fixed in the Linux kernel. Take the distro kernel update (RHEL/Rocky, Ubuntu, SLES) and reboot the host - no firmware, VBIOS or AGESA step. On a GPU fleet this is a cordon, drain and rolling reboot; plan it as normal kernel maintenance.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.