SB20260727207 - Improper handling of exceptional conditions in Linux kernel s390 mm



SB20260727207 - Improper handling of exceptional conditions in Linux kernel s390 mm

Published: July 27, 2026

Security Bulletin ID SB20260727207
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper handling of exceptional conditions (CVE-ID: CVE-2026-64369)

CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exception handling in load_unaligned_zeropad() and the s390 secure storage access exception handler when reading unaligned data across page boundaries involving donated secure-execution pages. A local user can trigger the vulnerable kernel access pattern to cause a denial of service.

The issue can result in an endless exception loop when the second page access raises an exception for pages donated to the Ultravisor for secure execution purposes.


Remediation

Install update from vendor's website.