Description
In the Linux kernel, the following vulnerability has been resolved:

s390/dasd: Guard sysfs discipline callbacks against unallocated private data

Several sysfs show/store handlers call a discipline callback that
dereferences device->private, either directly or through the
DASD_DEFINE_ATTR() macro. During dasd_generic_set_online() the discipline
is assigned before check_device() allocates device->private, so an
unprivileged read of one of these world-readable attributes in that window
dereferences a NULL pointer and panics.

Guard the dereference inside each callback that actually touches
device->private.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel panic
Action: Immediate Patch
AI Analysis

Impact

A null-pointer dereference exists in the s390 DASD driver when sysfs show/store handlers call a discipline callback that accesses device->private before that member is allocated. During dasd_generic_set_online the callback is registered immediately, and if an unprivileged user reads a specific sysfs attribute during a short window the kernel dereferences a NULL pointer and triggers a panic, causing the system.

Affected Systems

All Linux kernel builds containing the s390 DASD driver before the patch are affected. The exact kernel versions affected are not listed, but any kernel that has not incorporated the recent commit fixing the guard on sysfs callbacks is vulnerable.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate severity. The EPSS score of 0.00168 (< 1%) indicates an extremely low exploitation probability, and the issue is not in CISA’s KEV catalog. Exploitation requires an unprivileged user to read a specific sysfs attribute during a brief allocation window created by dasd_generic_set_online. While the window is narrow, the potential impact of a kernel panic is high, but practical exploitation is limited to systems using the affected driver.

Generated by OpenCVE AI on September 13, 2026 at 03:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch fixing the NULL pointer dereference in the s390 DASD driver.
  • If an upgrade is not yet possible, restrict or remove the world-readable sysfs attributes for the DASD driver, or disable the DASD subsystem when it is not needed.
  • Deploy a local security patch by applying the specific commit from the kernel repository or by building the kernel with the safety guard enabled for device->private access.
  • Monitor system logs for kernel panics or crashes related to dasd to detect accidental triggers during the allocation window.

Generated by OpenCVE AI on September 13, 2026 at 03:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Guard sysfs discipline callbacks against unallocated private data Several sysfs show/store handlers call a discipline callback that dereferences device->private, either directly or through the DASD_DEFINE_ATTR() macro. During dasd_generic_set_online() the discipline is assigned before check_device() allocates device->private, so an unprivileged read of one of these world-readable attributes in that window dereferences a NULL pointer and panics. Guard the dereference inside each callback that actually touches device->private.
Title s390/dasd: Guard sysfs discipline callbacks against unallocated private data
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:20.701Z

Reserved: 2026-09-11T19:38:34.707Z

Link: CVE-2026-89457

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:26.527

Modified: 2026-09-11T20:19:26.527

Link: CVE-2026-89457

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:20Z

Links: CVE-2026-89457 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T16:30:13Z

Weaknesses