SB2026082778 - Improper resource shutdown or release in Linux kernel s390 cio driver



SB2026082778 - Improper resource shutdown or release in Linux kernel s390 cio driver

Published: August 27, 2026

Security Bulletin ID SB2026082778
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper resource shutdown or release (CVE-ID: CVE-2026-80555)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in the vfio_ccw channel program initialization logic when processing channel programs containing Transfer in Channel segments. A remote attacker can trigger cp_init() failure during ccwchain construction to cause a denial of service.

The issue occurs because cleanup does not release all allocated CCW segments if initialization fails before the channel program is marked initialized.


Remediation

Install update from vendor's website.