In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/memencryptamd.c.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-48786.json"