Impact
The vulnerability in the Linux kernel’s s390/zcrypt subsystem stems from an incorrect upper‑bound check on the domain field of EP11 CPRB requests. The check was only enforced for custom device nodes, and as a result, requests sent with an administrative CPRB could bypass the bound and read or write memory located just beyond the perms->adm structure on the heap. Because this flaw occurs in kernel space, it can expose sensitive data or corrupt kernel memory, potentially allowing an attacker to gain elevated privileges or disrupt service. The fix adds an explicit limit of AP_DOMAINS=256 to enforce the correct upper bound.
Affected Systems
Affected systems include all Linux kernel implementations that include the s390/zcrypt module. The vulnerability is present in all kernel releases prior to the fix commit, regardless of distribution, because the commit modifies core kernel code. The patch is included in subsequent kernel releases; the exact version affected is not enumerated in the advisory, but any kernel before the fix must be upgraded.
Risk and Exploitability
Kernel memory corruption is high severity; the CVSS score is not provided in the advisory, but the nature of the flaw suggests a high exploitability. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the zcrypt subsystem when an attacker can craft a custom EP11 CPRB with an out‑of‑range domain value. Without sufficient system isolation, a local user with ability to write to the zcrypt device or an external attacker using a compromised crypto card could trigger the bug. The impact could be local privilege escalation or denial of service, depending on how the corrupted memory is leveraged.
OpenCVE Enrichment