Impact
An insecure state in the kernel's VFIO AP driver leaves a stale pointer in kvm->arch.crypto.pqap_hook when a matrix mdev attachment fails. The pointer remains pointing to freed memory, allowing the guest to execute PQAP instructions that dereference it. This use‑after‑free can corrupt kernel memory, potentially enabling an attacker in a privileged guest or one able to attach a mdev to trigger code execution in kernel space.
Affected Systems
The flaw affects the Linux kernel’s s390 platform VFIO AP interface. Prior to the patch commit 13bfc94eef389bd664ffc67b00184919902c938a, any kernel running on an s390 machine that loads the vfio‑ap driver and attaches matrix mdevs to KVM instances is vulnerable. The problem exists in kernel releases prior to the inclusion of the commit chain referenced above. It occurs when a second mdev attempts to bind to a KVM instance already owned by another matrix mdev.
Risk and Exploitability
The CVSS v3.1 base score is 8.8, indicating high severity. The EPSS score is below 1 %, signaling that, according to current threat data, the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require a local attacker with permissions to attach matrix mdevs to a KVM or a compromised privileged guest able to send PQAP instructions that trigger the dereference. The weakness stems from improper locking and pointer cleanup (improper synchronization), resulting in a use‑after‑free condition.
OpenCVE Enrichment
Debian DLA
Debian DSA