Out of Bounds Vulnerability in Linux Kernel Affecting s390/vfio_ccw
CVE-2026-80550
What is CVE-2026-80550?
A vulnerability in the Linux kernel's handling of channel command words (CCWs) in the s390/vfio_ccw driver allows for out-of-bounds memory access. The flaw arises from an incorrect loop condition in the ccwchain_calc_length() function, which attempts to examine memory beyond valid index ranges, specifically when counting CCWs in a single channel program. By failing to properly validate the number of CCWs, the function risks exposing the system to potential memory corruption which could lead to unpredictable behavior or security breaches. This issue has been addressed by restructuring the loop to prevent such out-of-bounds checks which could access beyond the defined limits.
Affected Version(s)
Linux 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 0282fb1c4b638eecfe2cc558092c460911d8f7e2
Linux 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 907adc667d902fafbdb2d740d57b55bd025dc4cd
Linux 0a19e61e6d4c6192077ead760ba0a2d350987d4c