Workqueues Vulnerability in Linux Kernel Affecting s390/vfio_ccw by Multiple Vendors
CVE-2026-80553
Currently unrated
What is CVE-2026-80553?
A vulnerability has been identified in the Linux kernel within the s390 architecture, specifically related to the vfio_ccw component. The issue arises from the insufficient uninitialization of workqueues (io_work and crw_work), leading to potential security risks. In the event that the private structure is freed, work may still be dispatched, resulting in undefined behavior or possible exploitation. Developers have addressed this by incorporating appropriate cleanup tags in the _release_dev function, thereby ensuring proper management of workqueues and enhancing overall system integrity.
Affected Version(s)
Linux e5f84dbaea59b4f712dac428c337528b70e1c533
Linux e5f84dbaea59b4f712dac428c337528b70e1c533
Linux e5f84dbaea59b4f712dac428c337528b70e1c533