PT-2026-93601 · Linux · Linux Kernel
CVE-2026-89960
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the s390 vfio-ap component. In the
vfio ap mdev set kvm() function, the kvm->arch.crypto.pqap hook pointer is assigned before update locks are acquired and the mdev list is verified. If another mdev is already attached to the KVM instance, the function returns an error without restoring the pointer. Because matrix mdev->kvm is not set during this error path, the vfio ap mdev unset kvm() function fails to clean up the hook when the mdev is closed. If the mdev is subsequently freed, any PQAP instruction executed by the guest will dereference a stale pointer via pqap hook rwsem, leading to a use-after-free condition. Additionally, a potential deadlock was identified in vfio ap mdev unset kvm() where kvm put kvm() was called while kvm->lock was held.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel