Improper locking in Linux kernel - CVE-2026-89956
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to cause kernel memory corruption or a use-after-free condition.
The vulnerability exists due to improper locking in the s390 VFIO AP mediated-device list handling when concurrently creating, removing, or looking up mediated devices. A local user can concurrently manipulate mediated devices to cause kernel memory corruption or a use-after-free condition.