Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Zero initialize data structures for inject_pfault_token

__kvm_inject_pfault_token() only sets .type and .u.ext.ext_params2 of
the on-stack struct kvm_s390_irq but the full ext substructure is copied
into the cpu local variable on inject. ext_params and pad contain stale
stack values.

Interrupt delivery only uses ext_params2, so nothing leaks to the guest,
but a host user can use the migration ioctls to get to the data.

Fix by zero-initializing the irq struct.
Do the same for the inti data structure.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The defect exists in the kvm_s390 module of the Linux kernel where the function __kvm_inject_pfault_token() fails to fully zero‑initialize a kvm_s390_irq structure. The uninitialized ext substructure retains stale stack values that can be read by a host user through the KVM migration ioctls. This results in leakage of kernel data to the host privileged user, qualifying as an information‑disclosure vulnerability. The flaw is a case of improper initialization and exposure of uninitialized data.

Affected Systems

All Linux kernel builds that include the KVM s390 driver are vulnerable. The issue is fixed by the commit that zero‑initializes the irq and related data structures; systems running kernels before that commit are impacted.

Risk and Exploitability

The EPSS score is below 1%, indicating a currently low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user with the ability to invoke KVM migration ioctls, which is typically a user with CAP_SYS_ADMIN or root privileges. Once the kernel is updated, the stale values are zeroed and the leakage vector is closed.

Generated by OpenCVE AI on September 18, 2026 at 07:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the KVM s390 patch that zero‑initializes inject_pfault_token and other related structures.
  • If an immediate kernel upgrade is not feasible, disable migration interfaces for KVM (for example, remove KVM architecture migration support or restrict migration sysfs entries) until the patch is deployed.
  • Restrict permission for the KVM migration ioctls to a minimal set of users or replace them with a least‑privilege configuration so that only trusted users can invoke migration functions.
  • Subscribe to vendor security advisories and monitor for kernel updates that address this issue.

Generated by OpenCVE AI on September 18, 2026 at 07:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Zero initialize data structures for inject_pfault_token __kvm_inject_pfault_token() only sets .type and .u.ext.ext_params2 of the on-stack struct kvm_s390_irq but the full ext substructure is copied into the cpu local variable on inject. ext_params and pad contain stale stack values. Interrupt delivery only uses ext_params2, so nothing leaks to the guest, but a host user can use the migration ioctls to get to the data. Fix by zero-initializing the irq struct. Do the same for the inti data structure.
Title KVM: s390: Zero initialize data structures for inject_pfault_token
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:51.402Z

Reserved: 2026-09-11T19:38:34.775Z

Link: CVE-2026-89921

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:01.173

Modified: 2026-10-03T11:17:44.770

Link: CVE-2026-89921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses

No weakness.