Impact
This vulnerability resides in the Linux kernel’s KVM s390 implementation, where the hypervisor attempts to forward CK machine checks from the host channel subsystem into the guest environment. The forwarded check can corrupt memory, causing an out‑of‑bounds write or an improper free of a stack variable that was observed by sashiko. The impact is a memory corruption that can potentially be leveraged for privilege escalation within the VM or to destabilize the hosted services. The weakness is a classic memory corruption flaw that can compromise integrity and availability of the guest system and may also affect the host if the check manipulation reaches kernel space.
Affected Systems
All Linux kernel distributions that include the s390 KVM subsystem are affected. The vulnerability is present in any kernel version lacking the patch that removes CK machine check reinjection. No specific vendor or version is listed, so any active Linux kernel deployed with s390 KVM is potentially compromised.
Risk and Exploitability
The CVSS score of 7.8 indicates substantial severity, and with an EPSS score of less than 1% the probability of exploitation is low but not negligible. The vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector involves a malicious or compromised guest that can trigger a CK machine check, but the attacker would need to exploit the kernel’s hypervisor path to achieve memory corruption, which limits the ease of exploitation. Nonetheless, the high CVSS warrants patching as the potential damage to guest and host systems is significant if successfully abused.
OpenCVE Enrichment