Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-74515
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper state validation in kvm_s390_pci_aif_enable() when handling repeated requests to enable adapter interrupt forwarding for the same zPCI device. A local user can issue the ioctl multiple times to cause a denial of service.
The issue can also overwrite and leak resources if the operation is invoked repeatedly for the same device.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74515
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/591952b63a9f976da7d49f719f36ec826ee2a575
- https://git.kernel.org/stable/c/6837f0ae85fd54cf64c8a0c7c530bba2fae0a207
- https://git.kernel.org/stable/c/6be1ff49ba81f96a6fa55915e6d920be43ac57cc
- https://git.kernel.org/stable/c/78d9648e7e960546d5b72504a0b0358cd8bb1e9d
- https://git.kernel.org/stable/c/8fa01be5a6149404adb82c0979a78f6347edd3ef