Description
In the Linux kernel, the following vulnerability has been resolved:

s390/vfio-ap: Fix NULL deref in status_show() during queue probe

When vfio_ap_mdev_probe_queue() creates the sysfs attribute group,
the queue's driver data has not yet been set. A concurrent read of
the 'status' attribute can therefore call dev_get_drvdata() and
get NULL, which is then passed directly to
vfio_ap_mdev_for_queue() where q->apqn is unconditionally
dereferenced, causing a NULL pointer dereference.

Fix this by acquiring the update locks before calling
sysfs_create_group(). The status_show() function acquires
guests_lock before reading the driver data, so any concurrent
read will block until after dev_set_drvdata() has been called
and the update locks are released.

As a bonus, the APQN no longer needs to be read from the queue
struct after allocation — it can be read directly from apdev
before allocation and stored in a local variable, which is then
assigned to q->apqn once the allocation succeeds.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: NULL pointer dereference leading to kernel panic and denial of service
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the s390/vfio‑ap driver within the Linux kernel. During the creation of the sysfs attribute group for a virtual function I/O AP queue, the queue’s driver data has not yet been set. If the status attribute is read concurrently, the code attempts to dereference a NULL driver data pointer, resulting in a kernel panic. The vulnerability is a race condition that can trigger a null pointer dereference, rendering the affected system unavailable until reboot or until the problem is resolved. Its impact is limited to causing a crash and service interruption; it does not directly lead to remote code execution or information disclosure.

Affected Systems

Linux kernel versions on s390 architecture that include the vfio‑ap driver are impacted. The issue appears in any kernel build that contains the vfio_ap_mdev_probe_queue function and the associated status_show method before the patching commit. The specific kernel patches in the supplied git log demonstrate the fix for these systems.

Risk and Exploitability

The CVSS score is not specified, but the EPSS rating of less than 1% suggests that the probability of exploitation in the wild is currently very low. The flaw is not listed in the CISA KEV catalog, indicating it has not been widely exploited. The attack vector is inferred to require a privileged local user able to trigger the queue probe while simultaneously reading the sysfs status attribute – a scenario possible if a user has root or elevated access. Because the exploit causes a crash rather than information leakage or privilege escalation, the main risk is denial of service. However, if the system is routinely rebooted, an attacker could repeatedly force the crash to impair availability.

Generated by OpenCVE AI on September 18, 2026 at 07:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the vfio‑ap driver fix
  • Apply any vendor‑supplied security updates for the s390 platform
  • Reboot the system to load the updated kernel and activate the fix

Generated by OpenCVE AI on September 18, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix NULL deref in status_show() during queue probe When vfio_ap_mdev_probe_queue() creates the sysfs attribute group, the queue's driver data has not yet been set. A concurrent read of the 'status' attribute can therefore call dev_get_drvdata() and get NULL, which is then passed directly to vfio_ap_mdev_for_queue() where q->apqn is unconditionally dereferenced, causing a NULL pointer dereference. Fix this by acquiring the update locks before calling sysfs_create_group(). The status_show() function acquires guests_lock before reading the driver data, so any concurrent read will block until after dev_set_drvdata() has been called and the update locks are released. As a bonus, the APQN no longer needs to be read from the queue struct after allocation — it can be read directly from apdev before allocation and stored in a local variable, which is then assigned to q->apqn once the allocation succeeds.
Title s390/vfio-ap: Fix NULL deref in status_show() during queue probe
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:39.064Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89955

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:05.797

Modified: 2026-09-16T11:17:05.797

Link: CVE-2026-89955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses

No weakness.