Vulnerability in Linux Kernel Affecting KVM on S390 Architecture
CVE-2026-80891

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80891?

A vulnerability has been identified in the Linux kernel's KVM subsystem for the s390 architecture. The flaw centers around improper validation of AIBV and AISB structures prior to pinning guest memory pages. Specifically, if the AIBV, which is a bit vector for MSI-X vectors, exceeds a single page boundary, the request should be rejected to prevent unsafe memory pinning. Additionally, any request with an unaligned AISB address, contrary to the requirement for doubleword alignment, is also rejected. This mechanism is crucial for maintaining the integrity and security of virtualized environments running on the s390 architecture, ensuring that memory operations remain within safe operational limits.

Affected Version(s)

Linux 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc < 3a1c64220ede4ac9ef9a3e76f008ff60a34f4c48

Linux 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc

Linux 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc < 15df7700dd99f8a37f5c6ed2dcf1e33009cdba47

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.