Impact
An issue in the Linux kernel’s s390 debugging subsystem can cause a deadlock when an s390 database file area is unregistered while a user is writing to one of its debugfs files. The code path holding a global debug mutex leads to a cycle of lock acquisition and waiting that stalls the system. The fix splits the unregister routine, reducing mutex contention to only the s390dbf component. The vulnerability is notable because it can bring the kernel to a halt, resulting in a denial of service for all users on the affected system.
Affected Systems
The affected product is the Linux kernel. Any kernel version that contains the legacy s390/debug unregister implementation before the patch commits (all releases prior to the commits linked in the advisory) is susceptible. The patch has been applied in [commit a08b70ed2d1ec907353a72f15163b8e34ff4b2f8] and related commit refs. All users of the Linux kernel running on s390 hardware without these updates are impacted.
Risk and Exploitability
The vulnerability has no publicly known exploits and is listed as not in the CISA KEV catalog. Its EPSS score is less than 1%, indicating a very low probability of exploitation. Nevertheless, an attacker with local, privileged access could trigger the deadlock by interleaving a write to a debugfs file with a module unload or kernel module removal, leading to a system freeze. The impact is limited to denial of service, with no compromise of confidentiality or integrity.
OpenCVE Enrichment
Debian DLA
Debian DSA