Impact
A race condition was identified in the KVM subsystem for the s390 architecture where page table entries could become unmapped between two internal functions. The vulnerability could lead to inconsistent memory mapping within the kernel, which in turn has the potential to corrupt kernel memory. The description does not explicitly state the exploitability beyond this possible memory corruption, so any claim beyond that is merely inferred from the nature of the race condition.
Affected Systems
Any Linux kernel installation that enables KVM on the s390 architecture is potentially affected. The CVE entry does not specify a particular kernel version range, so all kernels running the s390 KVM implementation before the referenced commits should be considered vulnerable.
Risk and Exploitability
The entry now includes an EPSS score of <1% and it is not listed in the CISA KEV catalog. The race condition could lead to kernel memory corruption, but no public exploits are known and the exploitation probability is low. With a CVSS score of 9.3 the vulnerability is classified as high severity, yet the low EPSS suggests a low likelihood of exploitation. As a result, the overall risk can be considered moderate to high, but because the flaw resides in core kernel code and carries a high severity score, it is advisable to apply the fix as soon as possible.
OpenCVE Enrichment