Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
High

Linux kernel TDX guest quote buffer length out-of-bounds read

IdentifiersCVE-2026-31470CWE-125

CVE-2026-31470 is a Linux kernel vulnerability in the virt: tdx-guest component affecting TDX guest remote attestation handling. The flaw arises from trusting the host-controlled field quote_buf->out_len, which determines how many bytes of the attestation quote are copied from the shared quote buffer to guest userspace. If the host supplies a length larger than the guest-allocated buffer, or races modification of the response while the guest is consuming it, the guest can read data beyond the pages allocated for quote_buf up to TSM_REPORT_OUTBLOB_MAX. The issue was fixed by validating quote_buf->out_len before copying data to userspace.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can disclose memory contents beyond the intended quote buffer to guest userspace. Because TDX quotes may be forwarded to remote attestation services, the leaked data can be exfiltrated off-system as part of attestation requests. SUSE notes that in deployments exposing per-container configs-tsm-report interfaces, the disclosure may cross container isolation boundaries and is not necessarily limited to local root-only impact. The issue is primarily a confidentiality flaw, with possible availability impact reflected in vendor scoring.

Mitigation

If you can’t patch tonight, do this now.

Until patched, reduce exposure by disabling or restricting TDX guest remote attestation interfaces where feasible, especially per-container configs-tsm-report exposure. Limit access to attestation-related device or report interfaces to only trusted workloads, minimize opportunities for untrusted host influence in affected TDX deployments, and avoid forwarding attestation quotes from sensitive multi-tenant/containerized environments unless necessary. These are partial mitigations only; kernel update is the definitive fix.

Remediation

Patch, then assume compromise.

Apply a Linux kernel update that includes the virt: tdx-guest fix for host-controlled quote buffer length validation. Vendor advisories indicate fixed builds across supported SUSE product lines, including for example SLES/SLED 15 SP7 kernel packages 6.4.0-150700.53.55.1 or later, SLES 16.0 kernel packages 6.12.0-160000.33.1 or later, and corresponding fixed kernels for affected Micro and openSUSE releases. Reboot into the updated kernel after installation.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
LinuxLinux Kerneloperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

ACTIVITY FEED

Recent activity

4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.

No news coverage yet. Advisories and community discussion only.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.