Description
In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Fix length check __import_wp_info()

struct kvm_hw_breakpoint::len is a __u64 that is fully controlled by user
space. This is then assigned to wp_info->len, which is an int. The bounds
check is done on the truncated value while the allocation uses the
untruncated one:

wp_info->len = bp_data->len;
[...]
if (wp_info->len < 0 || wp_info->len > MAX_WP_SIZE)
return -EINVAL;

wp_info->old_data = kmalloc(bp_data->len, GFP_KERNEL_ACCOUNT);

Use the validated value for the allocation as intended. Without this
fix userspace can trigger >4GB allocations which will fail and result
in a WARN due to MAX_PAGE_ORDER.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in the Linux kernel’s KVM module for the s390 architecture, where an unsigned 64‑bit field that represents a watchpoint size is stored in a 64‑bit integer and later copied into a signed 32‑bit integer without adequate bounds checking. The code performs a bounds check on the truncated 32‑bit value but uses the original 64‑bit length for memory allocation. This mismatch means a malicious user can request allocations larger than 4 GB, causing the kernel to attempt an oversized allocation that exceeds the MAX_PAGE_ORDER limit, triggering a WARN and potentially leading to kernel degradation and a local denial of service.

Affected Systems

The affected product is the Linux kernel running KVM on s390 systems. All kernel releases prior to the patch that introduced the length check are vulnerable. The fix targets the __import_wp_info() routine that processes watchpoint imports from user space.

Risk and Exploitability

The EPSS score indicates a very low likelihood of exploitation (<1 %). The vulnerability is not listed in CISA KEV, suggesting no publicly known exploits. The likely attack vector is through KVM’s watchpoint import interface, requiring the ability to send crafted watchpoint lengths from user space. Because the failure manifests as a WARN and not a direct crash or code execution, the immediate risk is a local denial of service rather than remote code execution. Nonetheless, patching remains the recommended response to eliminate potential instability.

Generated by OpenCVE AI on September 18, 2026 at 07:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the KVM s390 length check fix.
  • If upgrading cannot be performed immediately, restrict KVM usage to trusted processes or disable KVM on s390 until the patch is applied.
  • Continuously monitor kernel logs for WARN messages related to oversized allocation failures.

Generated by OpenCVE AI on September 18, 2026 at 07:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix length check __import_wp_info() struct kvm_hw_breakpoint::len is a __u64 that is fully controlled by user space. This is then assigned to wp_info->len, which is an int. The bounds check is done on the truncated value while the allocation uses the untruncated one: wp_info->len = bp_data->len; [...] if (wp_info->len < 0 || wp_info->len > MAX_WP_SIZE) return -EINVAL; wp_info->old_data = kmalloc(bp_data->len, GFP_KERNEL_ACCOUNT); Use the validated value for the allocation as intended. Without this fix userspace can trigger >4GB allocations which will fail and result in a WARN due to MAX_PAGE_ORDER.
Title KVM: s390: Fix length check __import_wp_info()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:18.785Z

Reserved: 2026-09-11T19:38:34.775Z

Link: CVE-2026-89926

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:01.777

Modified: 2026-09-16T11:17:01.777

Link: CVE-2026-89926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound