Description
In the Linux kernel, the following vulnerability has been resolved:

s390/dasd: Guard sysfs discipline callbacks against unallocated private data

Several sysfs show/store handlers call a discipline callback that
dereferences device->private, either directly or through the
DASD_DEFINE_ATTR() macro. During dasd_generic_set_online() the discipline
is assigned before check_device() allocates device->private, so an
unprivileged read of one of these world-readable attributes in that window
dereferences a NULL pointer and panics.

Guard the dereference inside each callback that actually touches
device->private.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel panic
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a null‑pointer dereference in the Linux kernel’s s390 DASD driver. When the driver registers a sysfs callback before allocating the device->private structure, an unprivileged user can read a world‑readable attribute during that narrow window and, leading to a kernel panic. This results in a denial of service that brings the entire system down.

Affected Systems

All Linux kernel builds containing the s390 DASD driver before the patch that adds guard checks are vulnerable. This includes any distribution whose kernel version packages the driver before the commit that protects sysfs callbacks, regardless of the device’s operational status, as the callbacks remain world‑readable.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity; the EPSS score of <1% reflects a very low likelihood of exploitation, and the flaw is not included in CISA’s KEV catalog. Exploitation requires an unprivileged user to access a specific sysfs attribute during the brief allocation window created by dasd_generic_set_online. Although the opportunity is narrow, the impact of a kernel panic is severe, compromising system availability.

Generated by OpenCVE AI on September 21, 2026 at 01:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the commit adding guard checks for sysfs callbacks in the s390 DASD driver.
  • If immediate kernel upgrade is not possible, restrict or remove world‑readable sysfs attributes for the DASD subsystem, or disable the DASD driver when it is not required.
  • Apply the specific kernel patch by retrieving the commit from the Linux repository or build the kernel with the guard enabled for device->private access.
  • Continuously monitor system logs for mentions of kernel panics or unexpected reboots associated with DASD to detect accidental triggers during the allocation window.

Generated by OpenCVE AI on September 21, 2026 at 01:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Guard sysfs discipline callbacks against unallocated private data Several sysfs show/store handlers call a discipline callback that dereferences device->private, either directly or through the DASD_DEFINE_ATTR() macro. During dasd_generic_set_online() the discipline is assigned before check_device() allocates device->private, so an unprivileged read of one of these world-readable attributes in that window dereferences a NULL pointer and panics. Guard the dereference inside each callback that actually touches device->private.
Title s390/dasd: Guard sysfs discipline callbacks against unallocated private data
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:57.812Z

Reserved: 2026-09-11T19:38:34.707Z

Link: CVE-2026-89457

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:26.527

Modified: 2026-09-14T13:19:02.093

Link: CVE-2026-89457

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:20Z

Links: CVE-2026-89457 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:15:03Z

Weaknesses