-
CVE-2026-89955
- EPSS 0.2%
- Veröffentlicht 16.09.2026 10:32:39
- Zuletzt bearbeitet 16.09.2026 11:17:05
- Erkennungen
s390/vfio-ap: Fix NULL deref in status_show() during queue probe
In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix NULL deref in status_show() during queue probe When vfio_ap_mdev_probe_queue() creates the sysfs attribute group, the queue's driver data has not yet been set. A concurrent read of the 'status' attribute can therefore call dev_get_drvdata() and get NULL, which is then passed directly to vfio_ap_mdev_for_queue() where q->apqn is unconditionally dereferenced, causing a NULL pointer dereference. Fix this by acquiring the update locks before calling sysfs_create_group(). The status_show() function acquires guests_lock before reading the driver data, so any concurrent read will block until after dev_set_drvdata() has been called and the update locks are released. As a bonus, the APQN no longer needs to be read from the queue struct after allocation — it can be read directly from apdev before allocation and stored in a local variable, which is then assigned to q->apqn once the allocation succeeds.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
260f3ea141382386e97611e7c2029bc013088ab1
Version <
31fa0a8a3c337ed2d200166d6926ab23c14f8b2e
Status
affected
Version
260f3ea141382386e97611e7c2029bc013088ab1
Version <
e102ce0f4af99dff769a4b1b4daa4cc6bd5ad2d9
Status
affected
Version
260f3ea141382386e97611e7c2029bc013088ab1
Version <
69632952aca04caa71e49953b6949fc04e788e67
Status
affected
Version
260f3ea141382386e97611e7c2029bc013088ab1
Version <
7db2511fc601ca3a6e3fb1bdce02261c3c3167c3
Status
affected
Version
260f3ea141382386e97611e7c2029bc013088ab1
Version <
dd6f4ef6f8a37412909ad787c837332fb070159c
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.0
Status
affected
Version
0
Version <
6.0
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.5
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.102 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/31fa0a8a3c337ed2d200166d6926ab23c14f8b2e
https://git.kernel.org/stable/c/e102ce0f4af99dff769a4b1b4daa4cc6bd5ad2d9
https://git.kernel.org/stable/c/69632952aca04caa71e49953b6949fc04e788e67
https://git.kernel.org/stable/c/7db2511fc601ca3a6e3fb1bdce02261c3c3167c3
https://git.kernel.org/stable/c/dd6f4ef6f8a37412909ad787c837332fb070159c