Impact
The first IDAW in a list of IDAs must remain unchanged between reads; if it changes, the computed size of the IDAL buffer can be incorrect, potentially causing the kernel to read memory beyond the intended region or otherwise corrupt kernel data structures. This flaw exposes the vfio_ccw driver to memory safety violations that could be leveraged to trigger a crash or other kernel exploitation. The vulnerability is driven by a failure to enforce a boundary condition in the vfio_ccw driver code on s390 architecture.
Affected Systems
Any Linux kernel build that includes the s390/vfio_ccw driver is potentially affected until the kernel is updated to include the patch that ensures the first IDAW value remains constant. No specific Linux kernel version range is provided, so all installations of the kernel with the vfio_ccw module should be treated as pending updates.
Risk and Exploitability
No CVSS or EPSS metrics are available and the vulnerability is not listed in the KEV catalog. The lack of public exploit evidence and the nature of the flaw suggest a moderate to high risk, especially for systems that use vfio_ccw devices. An attacker would need local or privileged access to deliver the exploit, making the attack vector likely to be a direct kernel exploitation scenario. The risk remains significant until the kernel bug is fixed via a patch or update.
OpenCVE Enrichment