CVE-2024-25742 and CVE-2024-25743 (WeSee) affect Linux virtual machines protected by AMD Secure Encrypted Virtualization–Secure Nested Paging (SEV-SNP). A malicious hypervisor can inject forged #VC exceptions, including interrupt 0x80, and manipulate the guest's EAX register. Because the guest handler may emulate an instruction without authenticating that it caused the exception, an attacker can induce writes of attacker-controlled data or disclose sensitive guest data, compromising VM confidentiality and integrity.
Red Hat rated each flaw moderate severity with a CVSS v3.1 score of 7.1 and released kernel fixes for affected Red Hat Enterprise Linux 8 and 9 streams, including selected Extended Update Support releases. Organizations operating SEV-SNP workloads should apply the applicable RHEL kernel updates and treat the hypervisor as a critical trust boundary; RHEL 6 and 7 kernel and kernel-rt packages are listed as not affected.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:3138 for the RHEL 8 kernel and RHSA-2024:2950 for kernel-rt to address CVE-2024-25742 and CVE-2024-25743.
Red Hat issued RHSA-2024:2758, fixing the affected RHEL 9 kernel for CVE-2024-25742 and CVE-2024-25743.
Red Hat released RHSA-2024:2627 for the RHEL 9.2 Extended Update Support kernel and RHSA-2024:2628 for kernel-rt, addressing the SEV-SNP interrupt-injection vulnerabilities.
Researchers responsibly disclosed WeSee (CVE-2024-25742), a malicious #VC interrupt-injection attack against AMD SEV-SNP guests, to AMD. The attack can enable guest-state leakage, memory corruption, and arbitrary guest-memory reads and writes from a malicious hypervisor.
Red Hat issued RHSA-2024:3810, fixing the affected RHEL 8.8 Extended Update Support kernel for CVE-2024-25742 and CVE-2024-25743.
Red Hat released RHSA-2024:3421, providing a kernel fix for the affected RHEL 9.0 Extended Update Support stream.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
8 references tracked. Mallory keeps watching after this page renders.
arxiv.org
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.