Impact
A race condition in the Linux kernel’s KVM implementation for the s390 architecture allows the KVM_S390_KEYOP operation to read the gmap->asce field without holding the mmu_lock while other components read it under the lock, potentially using a stale value that has been changed by gmap_set_limit(); this can corrupt kernel memory and destabilise the system, although the CVE does not describe further privilege escalation or data disclosure.
Affected Systems
This flaw targets the Linux kernel’s KVM subsystem on the s390 architecture; any kernel build that contains the affected code path is vulnerable until the patch that protects gmap->asce reads with mmu_lock is applied, so all Linux kernel versions prior to commit ae452b990e0544425f77045351c56e77158858e7 are potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS value of < 1 % and the absence from the CISA KEV catalog point to a low likelihood of exploitation; the likely attack vector requires a local privileged attacker who can trigger both keyop and a concurrent memory limit change, such as a host administrator or a privileged guest user, and even then success would rely on precise timing between the operations.
OpenCVE Enrichment