SB20260925138 - Use of Uninitialized Variable in Linux kernel s390 crypto driver
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of Uninitialized Variable (CVE-ID: CVE-2026-93238)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause unintended guest hardware queue resets.
The vulnerability exists due to use of an uninitialized bitmap in vfio_ap_mdev_hot_plug_cfg() when processing a hot-plug configuration change that adds only control domains. A local user can modify the hot-plug configuration to add only control domains to cause unintended guest hardware queue resets.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/09548edc6114f1eb1035b30795e893204ef45b85
- https://git.kernel.org/stable/c/4ba8a08f5f26ed59f356a6318bca3aa7cc0af3e2
- https://git.kernel.org/stable/c/6d554f2571e6b4db242593ba561efd6a6d1f99a9
- https://git.kernel.org/stable/c/bf09b9d7cd7890bc3a3b7eb63d5ece15f88bfde7
- https://git.kernel.org/stable/c/f73db632524320d2b93bc8534be8ea875053502d