Impact
The Linux kernel’s VFIO‑AP hot‑unplug logic on the s390 architecture fails to notify a running KVM guest when the last AP adapter, domain, or control domain is removed from the host. Because bitmap_andnot() returns false when the resulting bit map is empty, the do_hotplug flag remains zero and the guest’s shadow APCB is never updated. Consequently, a guest may continue to see or use a device that has been physically unplugged, allowing stale device descriptors to remain active and potentially enabling unintended access paths or configuration leakage.
Affected Systems
This issue affects the Linux kernel itself, specifically versions containing the VFIO‑AP hot‑unplug code prior to the patches linked in the advisory. All Linux distributions shipping these kernel versions on s390 platforms and using VFIO‑AP virtual devices are potentially impacted. Updated kernels that include the hot‑unplug fix are not affected.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is rated high. The EPSS score is <1 % and it is not listed in CISA’s KEV catalog, indicating a low overall exploitation probability in the field. However, the flaw is exploitable from within the host environment: a privileged user or hypervisor operator who can modify the AP configuration or issue an unplug command can trigger the bug. The result is persistent stale access to removed AP devices by the guest, which may undermine isolation and lead to resource exhaustion, unauthorized access, or subtle denial‑of‑service conditions. The attack vector requires host or hypervisor control rather than remote network access, making it a local privilege escalation or management‑level threat rather than an arbitrary code‑execution vector.
OpenCVE Enrichment
Debian DLA
Debian DSA