Impact
The vulnerability arises when the Linux kernel’s KVM for s390 fails to clear bits 64..255 of the crypto access bits that are shadowed from a format0 apcb, leaving stale data that a nested guest could use to gain access to a device that should no longer be available. This allows an attacker running a virtual machine to perform unauthorized access to hardware resources, compromising device isolation and potentially exposing sensitive data.
Affected Systems
The affected product is the Linux Kernel running on s390 architecture with KVM. No specific kernel versions are listed in the CVE data; remediation should apply to all versions susceptible prior to the kernel commit that introduced the zeroing of stale bits.
Risk and Exploitability
The flaw has a CVSS score of 8.8, indicating high severity. With no EPSS data, the probability of exploitation cannot be quantified at this time, but the absence from KEV suggests no known public exploits yet. The likely attack vector is a virtual machine running inside a KVM host on s390, which can trigger the stale crypto bits to grant unauthorized access to a device that should have been disallowed. Because the vulnerability enables bypassing of established isolation boundaries between nested guests and the host, it presents a high‑risk condition for systems that rely on KVM for s390 to provide security boundaries.
OpenCVE Enrichment
Debian DSA