KVM NULL Dereference Vulnerability in Linux Kernel Affecting IBM Systems
CVE-2026-80684
What is CVE-2026-80684?
In the Linux kernel, a potential NULL dereference vulnerability has been identified in the KVM module specifically affecting IBM systems. The issue occurs within the airq_iv_create() function, which can return NULL upon allocation failure. This scenario is not appropriately handled, leading to potential system errors when later attempting to use the NULL value in the kvm_zpci_set_airq() function. To mitigate this risk, a NULL check has been implemented along with proper memory management for previously allocated resources, ensuring system stability and security.
Affected Version(s)
Linux 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc < 96099486b63985801c9c6ef22505e9aa635b2d20
Linux 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc < 0a95abe964400771ad82b027d7b84a0d183cd0db
Linux 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc