Improper resource shutdown or release in Linux kernel - CVE-2026-80555
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the vfio_ccw channel program initialization logic when processing channel programs containing Transfer in Channel segments. A remote attacker can trigger cp_init() failure during ccwchain construction to cause a denial of service.
The issue occurs because cleanup does not release all allocated CCW segments if initialization fails before the channel program is marked initialized.