Impact
The defect exists in the kvm_s390 module of the Linux kernel where the function __kvm_inject_pfault_token() fails to fully zero‑initialize a kvm_s390_irq structure. The uninitialized ext substructure retains stale stack values that can be read by a host user through the KVM migration ioctls. This results in leakage of kernel data to the host privileged user, qualifying as an information‑disclosure vulnerability. The flaw is a case of improper initialization and exposure of uninitialized data.
Affected Systems
All Linux kernel builds that include the KVM s390 driver are vulnerable. The issue is fixed by the commit that zero‑initializes the irq and related data structures; systems running kernels before that commit are impacted.
Risk and Exploitability
The EPSS score is below 1%, indicating a currently low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user with the ability to invoke KVM migration ioctls, which is typically a user with CAP_SYS_ADMIN or root privileges. Once the kernel is updated, the stale values are zeroed and the leakage vector is closed.
OpenCVE Enrichment