SB2026082778 - Improper resource shutdown or release in Linux kernel s390 cio driver
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-80555)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the vfio_ccw channel program initialization logic when processing channel programs containing Transfer in Channel segments. A remote attacker can trigger cp_init() failure during ccwchain construction to cause a denial of service.
The issue occurs because cleanup does not release all allocated CCW segments if initialization fails before the channel program is marked initialized.
Remediation
Install update from vendor's website.