-

CVE-2026-74514

KVM: s390: pci: Fix memory accounting for pinned/unpinned pages

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: pci: Fix memory accounting for pinned/unpinned pages

The account_mem() and unaccount_mem() functions call get_uid() which
increments the reference count of struct user_struct on every invocation.
But we don't decrement the count by calling free_uid(). It also
accounted/unaccounted the pages against the current->mm. But its possible
the unaccount_mem() can be called from a different process context than the
one that originally pinned the pages.

Let's fix this by storing the pinning process user_struct and mm_struct
when accounting for pinned pages, and subsequently free these resources
when the pages are unpinned.

[borntraeger@linux.ibm.com: Fixed whitespace]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc
Version < ad1c2ac7f15b224cf9ab26b593caa9bd1a4be72e
Status affected
Version 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc
Version < dc7465a364104526c56b922c9de9dfcc08a7d5f7
Status affected
Version 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc
Version < 47cfd75d9df7c8f425b0d769328fe43a8a8e606e
Status affected
Version 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc
Version < 70871b121f81d08879363cb1238a4c85c5c2800c
Status affected
Version 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc
Version < e3f732e086e438c52c7400bd2734bb166aa4752c
Status affected
Version 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc
Version < 36f6999ecde3976731a8bfc0b8e667da6f593069
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.1.*
Version 6.1.184
Status unaffected
Version <= 6.6.*
Version 6.6.152
Status unaffected
Version <= 6.12.*
Version 6.12.104
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.065
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/70871b121f81d08879363cb1238a4c85c5c2800c
https://git.kernel.org/stable/c/e3f732e086e438c52c7400bd2734bb166aa4752c
https://git.kernel.org/stable/c/36f6999ecde3976731a8bfc0b8e667da6f593069
https://git.kernel.org/stable/c/47cfd75d9df7c8f425b0d769328fe43a8a8e606e
https://git.kernel.org/stable/c/dc7465a364104526c56b922c9de9dfcc08a7d5f7
https://git.kernel.org/stable/c/ad1c2ac7f15b224cf9ab26b593caa9bd1a4be72e