Impact
A missing lock protects the list of ap_matrix_mdev objects in the Linux kernel. When a probe or status call accesses the list without holding the proper mutex, concurrent creation or removal of matrix devices can corrupt kernel memory or result in a use‑after‑free of a device structure. This allows an attacker to execute arbitrary code in kernel mode, potentially leading to a privilege escalation or denial of service. The vulnerability is a classic improper synchronization race condition (CWE‑666) that directly impacts kernel integrity.
Affected Systems
All Linux kernel builds that include the s390/vfio‑ap driver, regardless of distribution, are affected until the patch that adds the correct guests_lock around list operations is applied. The vulnerability exists in every kernel variant that has the ap_matrix_mdev list handling code unpatched.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not compiled in CISA’s KEV list, indicating a low current exploitation probability. Nevertheless, because the flaw can lead to arbitrary kernel code execution, it remains a high‑severity threat once the code is present. The attack vector is inferred to be local privilege, requiring the ability to interact with the vfio‑ap device (e.g., by creating or removing a matrix guest).
OpenCVE Enrichment