Impact
When a virtual CPU on KVM for s390 is destroyed while hardware breakpoints or watchpoints remain active, the kernel does not clear the associated debug data structures. The unpurged information, which can include breakpoint and watchpoint details up to 8 KiB per virtual CPU and may accumulate over the lifetime of a virtual machine, is therefore leaked. This flaw falls under the CWE‑200 category of Information Exposure and could let a privileged adversary learn internal debugging state that is normally protected.
Affected Systems
All Linux kernel releases that support KVM on the s390 architecture are affected. No specific version range is provided, so any kernel using the referenced VCPU destroy path is at risk, regardless of distribution.
Risk and Exploitability
The EPSS score indicates an exploitation probability of less than 1 % and the vulnerability is not currently cataloged in the CISA KEV database. The likely attack vector is an attacker who can cause the virtual CPU to be destroyed—such as by terminating or crashing the virtual machine manager—or by gaining access to kernel memory dumps on a compromised host. Although the memory leak per VM is bounded, the leakage is cumulative across all VMs, potentially exposing a large amount of debug information over time. The overall risk is moderate, but the impact can be significant for environments that run many s390 VMs or that keep detailed debugging data on long‑lived workloads.
OpenCVE Enrichment
Debian DLA
Debian DSA