PT-2026-93601 · Linux · Linux Kernel

CVE-2026-89960

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the s390 vfio-ap component. In the vfio ap mdev set kvm() function, the kvm->arch.crypto.pqap hook pointer is assigned before update locks are acquired and the mdev list is verified. If another mdev is already attached to the KVM instance, the function returns an error without restoring the pointer. Because matrix mdev->kvm is not set during this error path, the vfio ap mdev unset kvm() function fails to clean up the hook when the mdev is closed. If the mdev is subsequently freed, any PQAP instruction executed by the guest will dereference a stale pointer via pqap hook rwsem, leading to a use-after-free condition. Additionally, a potential deadlock was identified in vfio ap mdev unset kvm() where kvm put kvm() was called while kvm->lock was held.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101528
CVE-2026-89960
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel