Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Fix old_data leak in guest debug error path

__import_wp_info() allocates a per-watchpoint old_data buffer to back up
the original guest memory contents. If a later watchpoint of the same
KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data()
jumps to the error label, which frees the wp_info array but not the
old_data buffers of the entries that were imported successfully. Up to
MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed
request, and the request can be repeated.

Create error handling for cleaning up all created old_data memory
areas.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak leading to Resource Exhaustion
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, a flaw in the handling of guest debug watchpoints results in an old_data buffer leak. When a KVM_SET_GUEST_DEBUG request fails after some watchpoints have been successfully imported, the cleanup routine releases the wp_info array but not the old_data buffers that were allocated for the successful entries. Each failed request can leak up to MAX_BP_COUNT‑1 buffers of up to MAX_WP_SIZE bytes of memory, and this process can be repeated an arbitrary number of times, potentially exhausting kernel memory and causing a denial‑of‑service condition for the hypervisor host.

Affected Systems

The affected product is the Linux kernel. No specific kernel version is listed, so any kernel that has not yet applied the patch is potentially vulnerable.

Risk and Exploitability

The EPSS score for this vulnerability is below 1 % and it is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The attack requires privileged access to the Kernel‑Virtual‑Machine (KVM) interface to issue KVM_SET_GUEST_DEBUG requests, so it is a local or privilege‑escalation vector rather than a remote network attack. If an attacker can repeatedly issue failing watchpoint configurations, they can force the kernel to leak memory until the hypervisor runs out of resources, resulting in a service disruption.

Generated by OpenCVE AI on September 18, 2026 at 03:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a Linux kernel update that includes the fix for the old_data memory leak
  • If an update is not immediately available, limit the use of KVM_SET_GUEST_DEBUG watchpoints or disable guest debugging features that trigger the vulnerable code path
  • Monitor kernel logs for repeated guest debug error messages that may indicate repeated failed requests and consider isolating or rebooting the host if memory exhaustion is observed

Generated by OpenCVE AI on September 18, 2026 at 03:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix old_data leak in guest debug error path __import_wp_info() allocates a per-watchpoint old_data buffer to back up the original guest memory contents. If a later watchpoint of the same KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data() jumps to the error label, which frees the wp_info array but not the old_data buffers of the entries that were imported successfully. Up to MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed request, and the request can be repeated. Create error handling for cleaning up all created old_data memory areas.
Title KVM: s390: Fix old_data leak in guest debug error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:17.442Z

Reserved: 2026-09-11T19:38:34.775Z

Link: CVE-2026-89924

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:01.527

Modified: 2026-09-16T11:17:01.527

Link: CVE-2026-89924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:30:02Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime