Impact
The vulnerability involves a memory leak in the KVM s390 guest debug handling. When a guest performs a KVM_SET_GUEST_DEBUG call, the kernel allocates bp_data but frees it only on error. Successful calls therefore leave a dangling allocation, leading to a memory leak that can grow unbounded if repeatedly invoked. This flaw is a classic memory management issue and matches CWE-401: Memory Leak.
Affected Systems
All Linux kernel releases that support the s390 KVM guest debug interface are affected; no specific version range is listed, so any kernel prior to the patch commits referenced in the advisory is vulnerable.
Risk and Exploitability
The EPSS score is below 1% and the CVE is not listed in CISA KEV, indicating a low probability of exploitation in the wild. The CVSS score of 5.5 points to moderate severity. The flaw requires privileged access to the guest debug API, meaning an attacker must have control of a guest that can issue KVM_SET_GUEST_DEBUG. No public exploit exists, so the primary risk is denial of service through resource exhaustion if the vulnerable calls are executed repeatedly.
OpenCVE Enrichment
Debian DLA
Debian DSA