PT-2026-93436 · Linux · Linux Kernel

CVE-2026-89795

·

Published

2026-09-16

·

Updated

2026-10-03

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description On s390 systems using a machine level hypervisor, PCI devices are accessed via PCI pass-through on a per PCI function granularity. A flaw exists in the s390 PCI hotplug driver where the pci create slot() function assigns the same pci slot object to multifunction devices. When attempting to reset a function through the reset slot() function (a wrapper for zpci hot reset device()), this shared assignment causes the incorrect function to be reset. Additionally, the issue leads to memory leaks because pci slot objects created for the function are not correctly freed in the pci slot release() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101147
CVE-2026-89795
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel