Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Free guest debug data on vcpu destroy

kvm_s390_clear_bp_data() is only called from
kvm_arch_vcpu_ioctl_set_guest_debug(), i.e. when user space changes or
disables debugging. A vCPU that is destroyed while hardware breakpoints
are still armed - the normal case when the VMM just exits or crashes -
leaks hw_bp_info, hw_wp_info and all old_data buffers, since generic KVM
frees the vCPU right after kvm_arch_vcpu_destroy().

That is bounded by MAX_BP_COUNT entries, so roughly 8 KiB per vCPU, but
it is unbounded over VM lifetimes. The allocations are
GFP_KERNEL_ACCOUNT, so the charge also outlives the exiting process and
pins dying memcgs.

Fix by clearing the debug data on vCPU destruction. Calling it
unconditionally is fine: struct kvm_vcpu is zero allocated, so for a vCPU
that never enabled debugging the counters are 0 and the pointers NULL.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

When a virtual CPU on KVM for s390 is destroyed while hardware breakpoints or watchpoints remain active, the kernel does not clear the associated debug data structures. The unpurged information, which can include breakpoint and watchpoint details up to 8 KiB per virtual CPU and may accumulate over the lifetime of a virtual machine, is therefore leaked. This flaw falls under the CWE‑200 category of Information Exposure and could let a privileged adversary learn internal debugging state that is normally protected.

Affected Systems

All Linux kernel releases that support KVM on the s390 architecture are affected. No specific version range is provided, so any kernel using the referenced VCPU destroy path is at risk, regardless of distribution.

Risk and Exploitability

The EPSS score indicates an exploitation probability of less than 1 % and the vulnerability is not currently cataloged in the CISA KEV database. The likely attack vector is an attacker who can cause the virtual CPU to be destroyed—such as by terminating or crashing the virtual machine manager—or by gaining access to kernel memory dumps on a compromised host. Although the memory leak per VM is bounded, the leakage is cumulative across all VMs, potentially exposing a large amount of debug information over time. The overall risk is moderate, but the impact can be significant for environments that run many s390 VMs or that keep detailed debugging data on long‑lived workloads.

Generated by OpenCVE AI on September 18, 2026 at 03:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel patch that clears debug data on vCPU destruction.
  • If a patch is unavailable, disable guest debugging features or ensure hardware breakpoints are never armed while the VMM is active.
  • Monitor VM and host logs for unusual memory access patterns and restrict privileged access to kernel memory areas where debugging data could reside.

Generated by OpenCVE AI on September 18, 2026 at 03:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Free guest debug data on vcpu destroy kvm_s390_clear_bp_data() is only called from kvm_arch_vcpu_ioctl_set_guest_debug(), i.e. when user space changes or disables debugging. A vCPU that is destroyed while hardware breakpoints are still armed - the normal case when the VMM just exits or crashes - leaks hw_bp_info, hw_wp_info and all old_data buffers, since generic KVM frees the vCPU right after kvm_arch_vcpu_destroy(). That is bounded by MAX_BP_COUNT entries, so roughly 8 KiB per vCPU, but it is unbounded over VM lifetimes. The allocations are GFP_KERNEL_ACCOUNT, so the charge also outlives the exiting process and pins dying memcgs. Fix by clearing the debug data on vCPU destruction. Calling it unconditionally is fine: struct kvm_vcpu is zero allocated, so for a vCPU that never enabled debugging the counters are 0 and the pointers NULL.
Title KVM: s390: Free guest debug data on vcpu destroy
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:16.765Z

Reserved: 2026-09-11T19:38:34.775Z

Link: CVE-2026-89923

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:01.397

Modified: 2026-09-16T11:17:01.397

Link: CVE-2026-89923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor