7.1

CVE-2026-80555

s390/vfio_ccw: Free all memory if cp_init() fails

In the Linux kernel, the following vulnerability has been resolved:

s390/vfio_ccw: Free all memory if cp_init() fails

The routine cp_free() is called to unpin/free any memory once an I/O
is completed successfully, or if cp_prefetch() fails. But if cp_init()
fails, and cp->initialized is not enabled, the same routine cannot be
used to free all the memory.

An attempt to address this exists in ccwchain_handle_ccw(), where a
single call to ccwchain_free() is made for the currently-processed
CCW segment. But this will leak other segments (created as a result
of a Transfer in Channel) that had been allocated as part of the same
channel program.

Address this by performing the cleanup outside of the recursive
ccwchain_handle_ccw()/ccwchain_loop_tic() logic.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8b515be512a2435bb8aedc6390cbe140167f9eb9
Version < 276bd7ed34d56c48c65c43c0b08f2ee77029b2fa
Status affected
Version 8b515be512a2435bb8aedc6390cbe140167f9eb9
Version < f9bcff265556796834122f95de16d52a8375206c
Status affected
Version 8b515be512a2435bb8aedc6390cbe140167f9eb9
Version < 17e01e342af74de12899c206dcc9ec90684703aa
Status affected
Version 8b515be512a2435bb8aedc6390cbe140167f9eb9
Version < 152fcb74a26804b70909381c6acc90595a0ae1c1
Status affected
Version 8b515be512a2435bb8aedc6390cbe140167f9eb9
Version < 6a917199aaf97904f5619afe3dfdacb155b03e8c
Status affected
Version 8b515be512a2435bb8aedc6390cbe140167f9eb9
Version < 32e3d364a7b8295120d37e6a6bd433d2de26f748
Status affected
Version 8b515be512a2435bb8aedc6390cbe140167f9eb9
Version < 4699b54fada156534cbb39834d47fc9374d7a1f5
Status affected
Version 8b515be512a2435bb8aedc6390cbe140167f9eb9
Version < 74186c2968f8f756ac3226b545b598457c910c75
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.3
Status affected
Version 0
Version < 5.3
Status unaffected
Version <= 5.10.*
Version 5.10.267
Status unaffected
Version <= 5.15.*
Version 5.15.218
Status unaffected
Version <= 6.1.*
Version 6.1.185
Status unaffected
Version <= 6.6.*
Version 6.6.154
Status unaffected
Version <= 6.12.*
Version 6.12.105
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.037
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 2.5 4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6a917199aaf97904f5619afe3dfdacb155b03e8c
https://git.kernel.org/stable/c/32e3d364a7b8295120d37e6a6bd433d2de26f748
https://git.kernel.org/stable/c/4699b54fada156534cbb39834d47fc9374d7a1f5
https://git.kernel.org/stable/c/74186c2968f8f756ac3226b545b598457c910c75
https://git.kernel.org/stable/c/152fcb74a26804b70909381c6acc90595a0ae1c1
https://git.kernel.org/stable/c/17e01e342af74de12899c206dcc9ec90684703aa
https://git.kernel.org/stable/c/276bd7ed34d56c48c65c43c0b08f2ee77029b2fa
https://git.kernel.org/stable/c/f9bcff265556796834122f95de16d52a8375206c