7.9

CVE-2026-80550

s390/vfio_ccw: Fix out of bounds check on CCW array

In the Linux kernel, the following vulnerability has been resolved:

s390/vfio_ccw: Fix out of bounds check on CCW array

The routine ccwchain_calc_length() counts the number of channel
command words (CCWs) that are chained together in a single channel
program, and rejects anything larger than CCWCHAIN_LEN_MAX (256) CCWs.

The loop itself is "do..while (count < 257)", and while the logic in
is_cpa_within_range() correctly adjusts between the 0-index array of
CCWs and the count of CCWs starting at 1, this means it would look
at a possible 257th CCW before ending the loop and (correctly)
returning an error.

Fix this by restructuring the loop to break as soon as 256 CCWs
(thus indexes 0-255) are examined, without looking at memory
outside the range.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 0a19e61e6d4c6192077ead760ba0a2d350987d4c
Version < 0282fb1c4b638eecfe2cc558092c460911d8f7e2
Status affected
Version 0a19e61e6d4c6192077ead760ba0a2d350987d4c
Version < 907adc667d902fafbdb2d740d57b55bd025dc4cd
Status affected
Version 0a19e61e6d4c6192077ead760ba0a2d350987d4c
Version < f20be33d093ce7630c17ff7ed93caf7eaf8ac1a3
Status affected
Version 0a19e61e6d4c6192077ead760ba0a2d350987d4c
Version < af3f80ca4c8b17f20f9e588def076288fdb49e65
Status affected
Version 0a19e61e6d4c6192077ead760ba0a2d350987d4c
Version < 499a8a66b1598bfab97182aed15e0f1646074a3d
Status affected
Version 0a19e61e6d4c6192077ead760ba0a2d350987d4c
Version < 4c2e1d359d7a2b82cdf3254e4e480af9417f99fb
Status affected
Version 0a19e61e6d4c6192077ead760ba0a2d350987d4c
Version < d5d096cd9369e986d4e5153baa86b8b35c283e09
Status affected
Version 0a19e61e6d4c6192077ead760ba0a2d350987d4c
Version < a005b7f1a491ffda61bff0fd0f6548f8986fb977
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.12
Status affected
Version 0
Version < 4.12
Status unaffected
Version <= 5.10.*
Version 5.10.266
Status unaffected
Version <= 5.15.*
Version 5.15.217
Status unaffected
Version <= 6.1.*
Version 6.1.184
Status unaffected
Version <= 6.6.*
Version 6.6.153
Status unaffected
Version <= 6.12.*
Version 6.12.105
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.9 2.5 4.7
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0282fb1c4b638eecfe2cc558092c460911d8f7e2
https://git.kernel.org/stable/c/907adc667d902fafbdb2d740d57b55bd025dc4cd
https://git.kernel.org/stable/c/f20be33d093ce7630c17ff7ed93caf7eaf8ac1a3
https://git.kernel.org/stable/c/af3f80ca4c8b17f20f9e588def076288fdb49e65
https://git.kernel.org/stable/c/499a8a66b1598bfab97182aed15e0f1646074a3d
https://git.kernel.org/stable/c/4c2e1d359d7a2b82cdf3254e4e480af9417f99fb
https://git.kernel.org/stable/c/d5d096cd9369e986d4e5153baa86b8b35c283e09
https://git.kernel.org/stable/c/a005b7f1a491ffda61bff0fd0f6548f8986fb977