SB2026082785 - Out-of-bounds write in Linux kernel s390 cio driver
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-80552)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information, modify memory, or cause a denial of service.
The vulnerability exists due to an out-of-bounds access in vfio_ccw region read and write handlers when processing read or write requests for vfio_ccw regions with an out-of-range region index. A local user can supply a crafted region index to disclose sensitive information, modify memory, or cause a denial of service.
The issue affects vfio_ccw read and write region handling on s390.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/649badf3a2fd8929e40198603a2cb21b74c21700
- https://git.kernel.org/stable/c/79ea5e0c4c8a9842ae85f45062d947b3297dfc07
- https://git.kernel.org/stable/c/988d9b5be3c2c4baf9457ce8e11b477e13eb9fcf
- https://git.kernel.org/stable/c/9f5f9a78fedc45bc29d6a0a64e3a3472361afae5
- https://git.kernel.org/stable/c/d3b1e38404b22df5a1f93019f2bb656feaad5ae3
- https://git.kernel.org/stable/c/d597fa1273802941c7801202135976fecc29672b