Race condition in Linux kernel - CVE-2026-80547
Published: August 27, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.
The vulnerability exists due to a race condition in the vfio_ccw crw handling logic when processing asynchronous hardware events and userspace reads of the crw region. A local user can trigger concurrent access to the crw list to disclose sensitive information, modify data, or cause a denial of service.
The issue affects the s390 vfio_ccw subsystem and involves the crw queue being accessed from asynchronous hardware-driven paths.