SB2026082787 - Out-of-bounds read in Linux kernel s390 cio driver
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-80550)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in ccwchain_calc_length() when processing chained channel command words in a channel program. A remote attacker can supply a crafted channel program to disclose sensitive information.
The issue occurs because the routine may examine a 257th CCW entry before rejecting an oversized chain.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0282fb1c4b638eecfe2cc558092c460911d8f7e2
- https://git.kernel.org/stable/c/499a8a66b1598bfab97182aed15e0f1646074a3d
- https://git.kernel.org/stable/c/4c2e1d359d7a2b82cdf3254e4e480af9417f99fb
- https://git.kernel.org/stable/c/907adc667d902fafbdb2d740d57b55bd025dc4cd
- https://git.kernel.org/stable/c/a005b7f1a491ffda61bff0fd0f6548f8986fb977
- https://git.kernel.org/stable/c/af3f80ca4c8b17f20f9e588def076288fdb49e65
- https://git.kernel.org/stable/c/d5d096cd9369e986d4e5153baa86b8b35c283e09
- https://git.kernel.org/stable/c/f20be33d093ce7630c17ff7ed93caf7eaf8ac1a3