标签
Blog post detailing the discovery of CVE-2026-53360, a heap out-of-bounds read/write in KVM's SEV-SNP Page State Change handler that lets a malicious guest corrupt host kernel memory. The author discusses the bug, his incorrect fix, the better fix from a duplicate reporter, and provides a CTF challenge.