Impact
The flaw resides in the s390/vfio‑ap driver within the Linux kernel. During the creation of the sysfs attribute group for a virtual function I/O AP queue, the queue’s driver data has not yet been set. If the status attribute is read concurrently, the code attempts to dereference a NULL driver data pointer, resulting in a kernel panic. The vulnerability is a race condition that can trigger a null pointer dereference, rendering the affected system unavailable until reboot or until the problem is resolved. Its impact is limited to causing a crash and service interruption; it does not directly lead to remote code execution or information disclosure.
Affected Systems
Linux kernel versions on s390 architecture that include the vfio‑ap driver are impacted. The issue appears in any kernel build that contains the vfio_ap_mdev_probe_queue function and the associated status_show method before the patching commit. The specific kernel patches in the supplied git log demonstrate the fix for these systems.
Risk and Exploitability
The CVSS score is not specified, but the EPSS rating of less than 1% suggests that the probability of exploitation in the wild is currently very low. The flaw is not listed in the CISA KEV catalog, indicating it has not been widely exploited. The attack vector is inferred to require a privileged local user able to trigger the queue probe while simultaneously reading the sysfs status attribute – a scenario possible if a user has root or elevated access. Because the exploit causes a crash rather than information leakage or privilege escalation, the main risk is denial of service. However, if the system is routinely rebooted, an attacker could repeatedly force the crash to impair availability.
OpenCVE Enrichment
Debian DLA
Debian DSA