Description
In the Linux kernel, the following vulnerability has been resolved:

s390/percpu: Fix MVIY_PERCPU() with older binutils

Commit a737737cdb9c ("s390/percpu: Infrastructure for more efficient
this_cpu operations") introduced MVIY_PERCPU(), which stringifies
arguments that are already C string literals. This generates an
assembler macro invocation with whitespace-separated quoted arguments:

GEN_MVIY "459712" "%r3"

GNU as versions prior to binutils 2.39 drop the separating whitespace
between quoted macro arguments during input scrubbing. They
consequently parse the invocation as a single argument and emit
repeated warnings:

Warning: missing closing `"'

The .ifc in GEN_MVIY never matches and GNU as exits successfully
without emitting the mviy instruction. As a result, the interrupted
per-CPU sequence is not marked in lowcore and the exception return
path cannot repair the per-CPU address register after migration.

All MVIY_PERCPU() callers pass C string literals. Use them directly
and separate the assembler macro arguments with an explicit comma. The
resulting invocation is:

GEN_MVIY 459712, %r3

This form is unambiguous for GNU as and LLVM's integrated assembler.
This behavior was fixed in GNU as from binutils 2.39, but Linux
supports binutils 2.30.
Published: 2026-09-11
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of service through kernel instability during CPU migration
Action: Rebuild Kernel
AI Analysis

Impact

The MVIY_PERCPU() macro in the s390 architecture expands C string literals into a GNU as macro invocation that older binutils versions collapse into a single argument, causing the macro to silently fail. The mviy instruction is omitted, leaving the per‑CPU sequence unmarked in lowcore. When an exception returns after a CPU migration the per‑CPU register cannot be restored, which can trigger a kernel crash or denial of service. This flaw is a CWE‑88 weakness and does not allow direct code execution that bypasses the kernel. The issue arises in kernels compiled with binutils versions earlier than 2.39, which drop separating whitespace between quoted macro arguments during input scrubbing, causing the compiler to produce malformed assembly.

Affected Systems

All Linux kernel builds that use the default binutils toolchain (version 2.30) or any older binutils when compiling the s390 architecture. Because the MVIY_PERCPU macro expands only when compiled against binutils older than 2.39, any kernel compiled with such toolchains will fail to emit the mviy instruction, leading to per‑CPU register issues during CPU migration. This applies to all modern Linux distributions that compile their kernel from source using a legacy toolchain.

Risk and Exploitability

The CVSS score of 7.0 reflects medium severity, while the EPSS score of < 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Inferred from the description, exploitation would require local‑root privileges, the ability to rebuild the kernel with an older binutils compiler, or control over the build environment. Consequently, the risk is limited to environments that rebuild the kernel with a legacy toolchain and perform CPU migration events, rather than remote attackers targeting running systems.

Generated by OpenCVE AI on September 21, 2026 at 01:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the binutils toolchain to version 2.39 or newer before building any kernel.
  • Rebuild and install the Linux kernel using the updated toolchain, ensuring MVIY_PERCPU expands correctly.
  • Conduct CPU migration tests in a controlled environment to confirm the per‑CPU registers are restored and no kernel crash occurs.

Generated by OpenCVE AI on September 21, 2026 at 01:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-88
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: s390/percpu: Fix MVIY_PERCPU() with older binutils Commit a737737cdb9c ("s390/percpu: Infrastructure for more efficient this_cpu operations") introduced MVIY_PERCPU(), which stringifies arguments that are already C string literals. This generates an assembler macro invocation with whitespace-separated quoted arguments: GEN_MVIY "459712" "%r3" GNU as versions prior to binutils 2.39 drop the separating whitespace between quoted macro arguments during input scrubbing. They consequently parse the invocation as a single argument and emit repeated warnings: Warning: missing closing `"' The .ifc in GEN_MVIY never matches and GNU as exits successfully without emitting the mviy instruction. As a result, the interrupted per-CPU sequence is not marked in lowcore and the exception return path cannot repair the per-CPU address register after migration. All MVIY_PERCPU() callers pass C string literals. Use them directly and separate the assembler macro arguments with an explicit comma. The resulting invocation is: GEN_MVIY 459712, %r3 This form is unambiguous for GNU as and LLVM's integrated assembler. This behavior was fixed in GNU as from binutils 2.39, but Linux supports binutils 2.30.
Title s390/percpu: Fix MVIY_PERCPU() with older binutils
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:29:33.766Z

Reserved: 2026-09-11T19:38:34.707Z

Link: CVE-2026-89459

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:26.780

Modified: 2026-09-13T07:17:09.733

Link: CVE-2026-89459

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:22Z

Links: CVE-2026-89459 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:00:09Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')