Description
In the Linux kernel, the following vulnerability has been resolved:

s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove

The vfio_ap_config_remove function uses the bitmap_andnot function to clear
bits from the matrix_mdev->matrix.adm bitmap (specifies the control domains
assigned to the mdev). This prevents the explicitly unplugged control
domains from being removed the KVM guest. The bitmap_and function is used
instead.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Persisting Control Domains
Action: Patch Immediate
AI Analysis

Impact

A logical flaw in the Linux kernel for the s390 architecture causes explicitly‑unplugged control domains to remain attached to a virtual machine. The bug stems from using the wrong bitmap operation during the vfio_ap_mdev_cfg_remove routine, which leaves control‑domain references in the guest’s matrix instead of clearing them. This flaw can enable a privileged attacker to retain unauthorized control over a virtual device, potentially allowing elevation of privilege or denial of service if the device is misused.

Affected Systems

All Linux kernel releases that run on the s390 architecture and do not yet include the commit that changes bitmap_andnot to bitmap_and in the vfio_ap_mdev_cfg_remove function are affected. Vendor‑specific distributions that ship the affected kernel from the source tree are covered, but no particular distribution version is listed.

Risk and Exploitability

The vulnerability scores a CVSS of 8.8, indicating high severity, while the EPSS score of <1% shows that, as of the latest data, exploitation is considered unlikely. The flaw is not listed in CISA’s KEV catalog, and no public exploit has been reported. Attackers would need to reach the host level or exploit KVM channel weaknesses to trigger the flaw. The likely attack vector is local or privileged code execution on the host, rather than remote exploitation.

Generated by OpenCVE AI on September 18, 2026 at 07:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the commit that corrects the bitmap operation in vfio_ap_mdev_cfg_remove.
  • If the system does not require vDPA functionality, blacklist or unload the vfio_ap module until the patch is applied.
  • Verify that control domains are properly removed after unplug actions by testing device connectivity in affected VMs.

Generated by OpenCVE AI on September 18, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-264

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove The vfio_ap_config_remove function uses the bitmap_andnot function to clear bits from the matrix_mdev->matrix.adm bitmap (specifies the control domains assigned to the mdev). This prevents the explicitly unplugged control domains from being removed the KVM guest. The bitmap_and function is used instead.
Title s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:38.868Z

Reserved: 2026-09-11T19:38:34.778Z

Link: CVE-2026-89959

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:06.320

Modified: 2026-09-16T15:18:20.433

Link: CVE-2026-89959

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses