Improper control of a resource through its lifetime in Linux kernel - CVE-2026-89795
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to reset an unintended PCI function and leak memory.
The vulnerability exists due to improper PCI slot assignment in the s390 PCI hotplug slot handling when requesting a function reset through the hotplug driver's slot_reset interface. A local user can request a reset for a PCI function to reset an unintended function and leak memory.
This occurs on s390 systems that expose the topology of multifunction PCI devices in a shared PCI domain.