Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: keyop: use mmu_lock to read gmap->asce

Every other dat_* consumer in this file (kvm_s390_get_skeys,
set_skeys, get_cmma_bits, set_cmma_bits, MEM_CLR_CMMA,
kvm_s390_fixup_prefix, kvm_test_age_gfn, kvm_age_gfn) reads
kvm->arch.gmap->asce *inside* the mmu_lock read-side. keyop is the only
outlier.

gmap->asce is mutated under write_lock(mmu_lock) by gmap_set_limit()
and keyop might use a stale asce value for walking as KVM_S390_KEYOP
and KVM_S390_VM_MEM_LIMIT_SIZE can run concurrently. This can result
in memory corruption.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Immediate Patch
AI Analysis

Impact

A race condition in the Linux kernel’s KVM implementation for the s390 architecture allows the KVM_S390_KEYOP operation to read the gmap->asce field without holding the mmu_lock while other components read it under the lock, potentially using a stale value that has been changed by gmap_set_limit(); this can corrupt kernel memory and destabilise the system, although the CVE does not describe further privilege escalation or data disclosure.

Affected Systems

This flaw targets the Linux kernel’s KVM subsystem on the s390 architecture; any kernel build that contains the affected code path is vulnerable until the patch that protects gmap->asce reads with mmu_lock is applied, so all Linux kernel versions prior to commit ae452b990e0544425f77045351c56e77158858e7 are potentially impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS value of < 1 % and the absence from the CISA KEV catalog point to a low likelihood of exploitation; the likely attack vector requires a local privileged attacker who can trigger both keyop and a concurrent memory limit change, such as a host administrator or a privileged guest user, and even then success would rely on precise timing between the operations.

Generated by OpenCVE AI on September 18, 2026 at 08:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the patch referenced in commit ae452b990e0544425f77045351c56e77158858e7 or apply a dedicated patch that enforces mmu_lock around gmap->asce reads.
  • Restrict or disable KVM on s390 for untrusted workloads and remove or limit keyop usage from guest contexts where possible.
  • Implement runtime monitoring for abnormal KVM memory states or unexpected crashes in the KVM modules to detect exploitation attempts early.

Generated by OpenCVE AI on September 18, 2026 at 08:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: s390: keyop: use mmu_lock to read gmap->asce Every other dat_* consumer in this file (kvm_s390_get_skeys, set_skeys, get_cmma_bits, set_cmma_bits, MEM_CLR_CMMA, kvm_s390_fixup_prefix, kvm_test_age_gfn, kvm_age_gfn) reads kvm->arch.gmap->asce *inside* the mmu_lock read-side. keyop is the only outlier. gmap->asce is mutated under write_lock(mmu_lock) by gmap_set_limit() and keyop might use a stale asce value for walking as KVM_S390_KEYOP and KVM_S390_VM_MEM_LIMIT_SIZE can run concurrently. This can result in memory corruption.
Title KVM: s390: keyop: use mmu_lock to read gmap->asce
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:12.561Z

Reserved: 2026-09-11T19:38:34.775Z

Link: CVE-2026-89919

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:00.967

Modified: 2026-09-16T15:18:18.130

Link: CVE-2026-89919

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:00:08Z

Weaknesses

No weakness.