Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Take srcu when importing watchpoint data

__import_wp_info() backs up the original guest memory contents of a
watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore
resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or
kvm->slots_lock) to be held, otherwise a concurrent memslot update can
free the memslots array under us once its SRCU grace period has elapsed.

As this is not fast path, following lock ordering (mutex first, then
srcu) take the big hammer and hold the srcu for the full import.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free
Action: Immediate Patch
AI Analysis

Impact

The KVM s390 subsystem contains a routine that imports watchpoint data by first backing up the original guest memory contents. The backup uses kvm_read_guest, which resolves memory slots via __kvm_memslots. If the srcu lock or slots_lock is not held when this read occurs, a concurrent memory‑slot update may free the slots array after the SRCU grace period. This race can cause a use‑after‑free of stack or kernel memory, potentially corrupting data or allowing an attacker to execute arbitrary code. The weakness is improper lock ordering and a race condition.

Affected Systems

The flaw exists in all releases of the Linux kernel that have not yet applied the srcu‑locking change for the KVM s390 watchpoint import function. It affects the Linux kernel KVM module on s390 hardware. No specific version numbers are provided, so any build prior to the patch that includes the srcu lock is considered vulnerable.

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as high severity, while the EPSS score of less than 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require a scenario where an attacker can trigger the watchpoint import while a concurrent memory‑slot update occurs; based on the description, the likely attack vector is a privileged or hypervisor‑controlled attacker with access to the guest memory space. Because the race is not on a fast path, the attack surface is limited, but a successful exploit could lead to a kernel crash or, in the worst case, remote code execution.

Generated by OpenCVE AI on September 18, 2026 at 08:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the srcu‑locking fix for the KVM s390 watchpoint import routine.
  • If the update is not yet available, apply a custom patch that acquires the srcu lock before any guest memory read during watchpoint import, ensuring proper locking order.
  • Until the kernel update or patch is applied, avoid using watchpoint import features in environments that perform memory‑slot updates, or disable KVM s390 watchpoint functionality if not required.

Generated by OpenCVE AI on September 18, 2026 at 08:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when importing watchpoint data __import_wp_info() backs up the original guest memory contents of a watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or kvm->slots_lock) to be held, otherwise a concurrent memslot update can free the memslots array under us once its SRCU grace period has elapsed. As this is not fast path, following lock ordering (mutex first, then srcu) take the big hammer and hold the srcu for the full import.
Title KVM: s390: Take srcu when importing watchpoint data
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:15.723Z

Reserved: 2026-09-11T19:38:34.775Z

Link: CVE-2026-89922

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:01.277

Modified: 2026-09-16T15:18:18.357

Link: CVE-2026-89922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:45:07Z

Weaknesses

No weakness.