Impact
A logical flaw in the Linux kernel for the s390 architecture causes explicitly‑unplugged control domains to remain attached to a virtual machine. The bug stems from using the wrong bitmap operation during the vfio_ap_mdev_cfg_remove routine, which leaves control‑domain references in the guest’s matrix instead of clearing them. This flaw can enable a privileged attacker to retain unauthorized control over a virtual device, potentially allowing elevation of privilege or denial of service if the device is misused.
Affected Systems
All Linux kernel releases that run on the s390 architecture and do not yet include the commit that changes bitmap_andnot to bitmap_and in the vfio_ap_mdev_cfg_remove function are affected. Vendor‑specific distributions that ship the affected kernel from the source tree are covered, but no particular distribution version is listed.
Risk and Exploitability
The vulnerability scores a CVSS of 8.8, indicating high severity, while the EPSS score of <1% shows that, as of the latest data, exploitation is considered unlikely. The flaw is not listed in CISA’s KEV catalog, and no public exploit has been reported. Attackers would need to reach the host level or exploit KVM channel weaknesses to trigger the flaw. The likely attack vector is local or privileged code execution on the host, rather than remote exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA