Impact
The KVM s390 subsystem contains a routine that imports watchpoint data by first backing up the original guest memory contents. The backup uses kvm_read_guest, which resolves memory slots via __kvm_memslots. If the srcu lock or slots_lock is not held when this read occurs, a concurrent memory‑slot update may free the slots array after the SRCU grace period. This race can cause a use‑after‑free of stack or kernel memory, potentially corrupting data or allowing an attacker to execute arbitrary code. The weakness is improper lock ordering and a race condition.
Affected Systems
The flaw exists in all releases of the Linux kernel that have not yet applied the srcu‑locking change for the KVM s390 watchpoint import function. It affects the Linux kernel KVM module on s390 hardware. No specific version numbers are provided, so any build prior to the patch that includes the srcu lock is considered vulnerable.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity, while the EPSS score of less than 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require a scenario where an attacker can trigger the watchpoint import while a concurrent memory‑slot update occurs; based on the description, the likely attack vector is a privileged or hypervisor‑controlled attacker with access to the guest memory space. Because the race is not on a fast path, the attack surface is limited, but a successful exploit could lead to a kernel crash or, in the worst case, remote code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA