Impact
The vulnerability arises when the vfio-ap driver accesses the kvm pointer through matrix_mdev->kvm without checking for NULL. If matrix_mdev->kvm has never been set, taking the kvm->lock mutex triggers a NULL pointer dereference, causing the kernel to crash. Attackers can leverage this to force a system reboot or a reboot loop, denying service to all users on the affected system, especially on s390 machines using the VFIO AP driver.
Affected Systems
The flaw affects the Linux kernel’s s390 VFIO AP subsystem. Any kernel version that includes the vfio_ap driver on the s390 architecture and lacks the null check is vulnerable. The specific product is the Linux Linux kernel; affected releases are those before the patch commit that introduces the NULL check for matrix_mdev->kvm.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a very low likelihood of exploitation in the wild. CISA KEV lists it as not listed, so no known active exploits. The attack would require local privilege or an environment where the system can load a guest that leaves matrix_mdev->kvm unset. Because the crash is locally exploitable, the severity is high, but the practical risk remains low due to the niche target and small attack surface.
OpenCVE Enrichment
Debian DLA
Debian DSA