Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: vsie: zero stale crypto bits

When shadowing crypto access bits from a format0 apcb (crycb 0 or 1),
the bits 64..255 are unchanged from whatever is in the vsie page in the
crycb and thus in the apcb. This gives a nested guest potential access
to a device no longer available. Zero out the remaining bits.
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized device access via stale crypto bits
Action: Apply patch
AI Analysis

Impact

The vulnerability arises when the Linux kernel’s KVM for s390 fails to clear bits 64..255 of the crypto access bits that are shadowed from a format0 apcb, leaving stale data that a nested guest could use to gain access to a device that should no longer be available. This allows an attacker running a virtual machine to perform unauthorized access to hardware resources, compromising device isolation and potentially exposing sensitive data.

Affected Systems

The affected product is the Linux Kernel running on s390 architecture with KVM. No specific kernel versions are listed in the CVE data; remediation should apply to all versions susceptible prior to the kernel commit that introduced the zeroing of stale bits.

Risk and Exploitability

The flaw has a CVSS score of 8.8, indicating high severity. With no EPSS data, the probability of exploitation cannot be quantified at this time, but the absence from KEV suggests no known public exploits yet. The likely attack vector is a virtual machine running inside a KVM host on s390, which can trigger the stale crypto bits to grant unauthorized access to a device that should have been disallowed. Because the vulnerability enables bypassing of established isolation boundaries between nested guests and the host, it presents a high‑risk condition for systems that rely on KVM for s390 to provide security boundaries.

Generated by OpenCVE AI on September 10, 2026 at 09:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix for zeroing stale crypto bits in KVM for s390.
  • If an immediate kernel update is not possible, restrict or disable nested virtualization on s390 hosts to prevent the guest from accessing the compromised crypto state.
  • Verify the integrity of the kernel and monitor for anomalous device access patterns that might indicate exploitation of stale crypto bits.

Generated by OpenCVE AI on September 10, 2026 at 09:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 10 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-790

Thu, 10 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-862

Thu, 10 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-862

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.
Title KVM: s390: vsie: zero stale crypto bits
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-10T05:50:22.520Z

Reserved: 2026-08-26T14:34:25.801Z

Link: CVE-2026-80921

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T17:17:47.240

Modified: 2026-09-10T06:17:06.037

Link: CVE-2026-80921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T18:45:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-790

    Improper Filtering of Special Elements