SB20260625215 - Out-of-bounds write in Linux kernel s390 kvm
Published: June 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-52968)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds access in the KVM s390 PCI GAIT handling code when processing AIF and host alert forwarding operations. A local user can trigger crafted GAIT index usage to cause a denial of service.
The issue is caused by double-scaling pointer arithmetic that accesses element aisb*16 instead of aisb, and out-of-bounds accesses occur when aisb is 32 or greater.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/11b8ff5b930b351dd1f6f088dce0beb027ac92d0
- https://git.kernel.org/stable/c/16d990a15491cf76cd6eef0846e1b4100e63261a
- https://git.kernel.org/stable/c/31a9d9f9942885aae356a1a57c79e82c5b5b0828
- https://git.kernel.org/stable/c/a99a25db131ece5e6c0f7632da606de631efe4f2
- https://git.kernel.org/stable/c/b22a2da8792a7bfe743c1a922e77fa499ddedbe8
- https://git.kernel.org/stable/c/e7216651b94e92e5433fb2f54b77864642b4ea48