Linux Kernel Vulnerability in VFIO CCW Affecting Multiple Versions
CVE-2026-80554

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-80554?

A flaw in the Linux kernel's handling of VFIO CCW can lead to an improper input validation issue due to recursive processing methods of channel programs. The vulnerability arises when the system encounters Transfer-In-Channel (TIC) CCWs, which could theoretically lead to an indefinite increase in the number of segments per channel program. Limitations imposed on the global count of segments ensure that this recursion does not compromise system stability until a thorough redesign can be achieved.

Affected Version(s)

Linux 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 15fb4559a7fdf0b8725e433a71cfd03a1313a48b

Linux 0a19e61e6d4c6192077ead760ba0a2d350987d4c

Linux 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 06f4d6e5a8af6c2072e8cd39dbc512c683ca7fb2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.