Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Fix memory corruption by not reinjecting CK machine checks

Channel-subsystem damage machine checks are for the host channel
subsystem. The guest channel subsystem is emulated in the userspace VMM.
There is no point in forwarding such machine checks into the guest.

This also simplifies the machine check reinjection and avoids kfree of a
stack variable as reported by sashiko. There might be still machine
checks that have the ck bit set with another bit (like instruction
damage), mask out the CK bit in s390_backup_mcck_info(), like the CP and
ED bits already are.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: KVM Machine Check Memory Corruption
Action: Immediate Patch
AI Analysis

Impact

This vulnerability resides in the Linux kernel’s KVM s390 implementation, where the hypervisor attempts to forward CK machine checks from the host channel subsystem into the guest environment. The forwarded check can corrupt memory, causing an out‑of‑bounds write or an improper free of a stack variable that was observed by sashiko. The impact is a memory corruption that can potentially be leveraged for privilege escalation within the VM or to destabilize the hosted services. The weakness is a classic memory corruption flaw that can compromise integrity and availability of the guest system and may also affect the host if the check manipulation reaches kernel space.

Affected Systems

All Linux kernel distributions that include the s390 KVM subsystem are affected. The vulnerability is present in any kernel version lacking the patch that removes CK machine check reinjection. No specific vendor or version is listed, so any active Linux kernel deployed with s390 KVM is potentially compromised.

Risk and Exploitability

The CVSS score of 7.8 indicates substantial severity, and with an EPSS score of less than 1% the probability of exploitation is low but not negligible. The vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector involves a malicious or compromised guest that can trigger a CK machine check, but the attacker would need to exploit the kernel’s hypervisor path to achieve memory corruption, which limits the ease of exploitation. Nonetheless, the high CVSS warrants patching as the potential damage to guest and host systems is significant if successfully abused.

Generated by OpenCVE AI on September 18, 2026 at 07:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update where the s390 KVM patch that removes CK machine check reinjection is included. This is the official solution from the vendor.
  • If an immediate kernel update is not possible, consider disabling s390 KVM on the host or disabling CK machine check reinjection features via KVM configuration if such settings exist. This removes the attack surface that relies on forwarding machine checks to the guest.
  • Monitor system logs (such as dmesg or /var/log/kern.log) for unexpected machine check events and investigate any anomalies immediately.

Generated by OpenCVE AI on September 18, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-590
CWE-787

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix memory corruption by not reinjecting CK machine checks Channel-subsystem damage machine checks are for the host channel subsystem. The guest channel subsystem is emulated in the userspace VMM. There is no point in forwarding such machine checks into the guest. This also simplifies the machine check reinjection and avoids kfree of a stack variable as reported by sashiko. There might be still machine checks that have the ck bit set with another bit (like instruction damage), mask out the CK bit in s390_backup_mcck_info(), like the CP and ED bits already are.
Title KVM: s390: Fix memory corruption by not reinjecting CK machine checks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:14.105Z

Reserved: 2026-09-11T19:38:34.775Z

Link: CVE-2026-89920

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:01.073

Modified: 2026-09-16T15:18:18.237

Link: CVE-2026-89920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:15:14Z

Weaknesses