Description
In the Linux kernel, the following vulnerability has been resolved:

s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed

The vfio_ap_mdev_hot_unplug_cfg() function uses the return value of
bitmap_andnot() to determine whether the guest APCB needs to be updated.
However, bitmap_andnot() returns false when the resulting destination
bitmap is empty. This means that if the only adapter, domain or control
domain assigned to an mdev is removed from the host's AP configuration,
the bit is correctly cleared from the shadow APCB, but bitmap_andnot()
returns false because the result is an empty bitmap. Consequently,
do_hotplug remains 0 and vfio_ap_mdev_update_guest_apcb() is never called,
leaving the KVM guest with stale hardware access to the unplugged AP
devices.

Fix this by replacing the bitmap_andnot() return value check with
bitmap_intersects() to determine whether the shadow APCB actually
overlaps with the removal mask. If there is an intersection, call
bitmap_andnot() solely for its side effect of clearing the bits, then
unconditionally set do_hotplug to trigger the guest APCB update.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stale hardware access in KVM guests due to skipped hot‑unplug update
Action: Patch
AI Analysis

Impact

The Linux kernel’s VFIO‑AP hot‑unplug logic on the s390 architecture fails to notify a running KVM guest when the last AP adapter, domain, or control domain is removed from the host. Because bitmap_andnot() returns false when the resulting bit map is empty, the do_hotplug flag remains zero and the guest’s shadow APCB is never updated. Consequently, a guest may continue to see or use a device that has been physically unplugged, allowing stale device descriptors to remain active and potentially enabling unintended access paths or configuration leakage.

Affected Systems

This issue affects the Linux kernel itself, specifically versions containing the VFIO‑AP hot‑unplug code prior to the patches linked in the advisory. All Linux distributions shipping these kernel versions on s390 platforms and using VFIO‑AP virtual devices are potentially impacted. Updated kernels that include the hot‑unplug fix are not affected.

Risk and Exploitability

With a CVSS score of 8.8 the vulnerability is rated high. The EPSS score is <1 % and it is not listed in CISA’s KEV catalog, indicating a low overall exploitation probability in the field. However, the flaw is exploitable from within the host environment: a privileged user or hypervisor operator who can modify the AP configuration or issue an unplug command can trigger the bug. The result is persistent stale access to removed AP devices by the guest, which may undermine isolation and lead to resource exhaustion, unauthorized access, or subtle denial‑of‑service conditions. The attack vector requires host or hypervisor control rather than remote network access, making it a local privilege escalation or management‑level threat rather than an arbitrary code‑execution vector.

Generated by OpenCVE AI on September 18, 2026 at 07:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the vfio‑ap hot‑unplug patch.
  • If an upgrade is not immediately possible, disable VFIO‑AP on the host or isolate the system from the untrusted domain until a reboot resets the guest state.
  • Configure the host to avoid hot‑unplug of AP devices; perform any adapter or domain removal during a controlled shutdown or maintenance window where the guest can be restarted and its device state refreshed.

Generated by OpenCVE AI on September 18, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed The vfio_ap_mdev_hot_unplug_cfg() function uses the return value of bitmap_andnot() to determine whether the guest APCB needs to be updated. However, bitmap_andnot() returns false when the resulting destination bitmap is empty. This means that if the only adapter, domain or control domain assigned to an mdev is removed from the host's AP configuration, the bit is correctly cleared from the shadow APCB, but bitmap_andnot() returns false because the result is an empty bitmap. Consequently, do_hotplug remains 0 and vfio_ap_mdev_update_guest_apcb() is never called, leaving the KVM guest with stale hardware access to the unplugged AP devices. Fix this by replacing the bitmap_andnot() return value check with bitmap_intersects() to determine whether the shadow APCB actually overlaps with the removal mask. If there is an intersection, call bitmap_andnot() solely for its side effect of clearing the bits, then unconditionally set do_hotplug to trigger the guest APCB update.
Title s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:37.364Z

Reserved: 2026-09-11T19:38:34.778Z

Link: CVE-2026-89957

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:06.043

Modified: 2026-09-16T15:18:20.280

Link: CVE-2026-89957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses

No weakness.