I found a KVM guest-to-host heap corruption bug and someone else got there first
Summary
The post documents a KVM SEV-SNP guest-to-host heap corruption vulnerability (CVE-2026-53360) found independently, detailing the vulnerability in the Page State Change handler, the patch timeline, and the debate over who fixed it. It includes a practical discussion of the vulnerability’s impact, a comparison of patches, and a defense-focused takeaway with a safe CTF for practice.