In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.
https://ahoi-attacks.github.io/
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html
https://github.com/torvalds/linux/commit/e3ef461af35a8c74f2f4ce6616491ddb355a208f