8.8

CVE-2026-80548

s390/vfio_ccw: Selectively expand io_mutex

In the Linux kernel, the following vulnerability has been resolved:

s390/vfio_ccw: Selectively expand io_mutex

The io_mutex was defined to serialize the io_regions, but then has
also sort of been associated with the I/O themselves because of
the close relationship they share.

With the handful of races that are possible, the choices are either to:
 A) expand the scope of io_mutex to close these remaining windows, or
 B) reduce the scope of io_mutex to just io_region, and introduce a new
    lock mechanism for the remaining I/O resources

This patch implements A, since B brings with it a lot more interactions
that would need to be tracked and kept in a correct hierarchy. It also
takes advantage of the workqueue element for cp_free() that now gets
called out of fsm_notoper(), which could be invoked out of an interrupt
context and thus cannot acquire a mutex itself.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4f76617378ee97c557b526cb58d3c61eb0a9c963
Version < dab6a6627b0b0cce23653e99c7b0bf8c6cfd82e0
Status affected
Version 4f76617378ee97c557b526cb58d3c61eb0a9c963
Version < 56d7488533ceac4e986e96e15c9e487a2245bc01
Status affected
Version 4f76617378ee97c557b526cb58d3c61eb0a9c963
Version < f72a51810d49411bd8cad0c2df8592320a2fe5cc
Status affected
Version 4f76617378ee97c557b526cb58d3c61eb0a9c963
Version < 2ba9efdf9ebedc4e54df4b56aa3b43a65f7967cd
Status affected
Version 4f76617378ee97c557b526cb58d3c61eb0a9c963
Version < b6aecea4b2b246f9fbd98a5712daa1193a60818e
Status affected
Version 4f76617378ee97c557b526cb58d3c61eb0a9c963
Version < 2a5ac0c0f1f7da33929211a2e41911bf72ee35d8
Status affected
Version 4f76617378ee97c557b526cb58d3c61eb0a9c963
Version < 34f4feff3e90bd09308fad0974e97113b23b812a
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.2
Status affected
Version 0
Version < 5.2
Status unaffected
Version <= 5.15.*
Version 5.15.218
Status unaffected
Version <= 6.1.*
Version 6.1.185
Status unaffected
Version <= 6.6.*
Version 6.6.153
Status unaffected
Version <= 6.12.*
Version 6.12.105
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.028
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f72a51810d49411bd8cad0c2df8592320a2fe5cc
https://git.kernel.org/stable/c/2ba9efdf9ebedc4e54df4b56aa3b43a65f7967cd
https://git.kernel.org/stable/c/b6aecea4b2b246f9fbd98a5712daa1193a60818e
https://git.kernel.org/stable/c/2a5ac0c0f1f7da33929211a2e41911bf72ee35d8
https://git.kernel.org/stable/c/34f4feff3e90bd09308fad0974e97113b23b812a
https://git.kernel.org/stable/c/56d7488533ceac4e986e96e15c9e487a2245bc01
https://git.kernel.org/stable/c/dab6a6627b0b0cce23653e99c7b0bf8c6cfd82e0