-

CVE-2026-93238

s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap

In the Linux kernel, the following vulnerability has been resolved:

s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap

The DECLARE_BITMAP(apm_filtered, AP_DEVICES) macro allocates the bitmap
on the stack without zero-initializing it.

In vfio_ap_mdev_hot_plug_cfg(), the vfio_ap_mdev_filter_matrix() function
is only called to initialize and populate apm_filtered if either
filter_adapters or filter_domains is true. If the hot plug configuration
change only adds control domains (meaning filter_cdoms is true, but
filter_adapters and filter_domains are both false),
vfio_ap_mdev_filter_matrix() is bypassed.

Consequently, apm_filtered is passed to reset_queues_for_apids() with
uninitialized stack garbage. This can cause reset_queues_for_apids() to
interpret arbitrary stack garbage bits as valid APIDs to reset, potentially
performing unintended guest hardware queue resets.

Fix this by zero-initializing the apm_filtered bitmap at the beginning of
vfio_ap_mdev_hot_plug_cfg() using bitmap_zero().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version eeb386aeb5b7c8d2dae6a3ba49255d8a97803182
Version < 4ba8a08f5f26ed59f356a6318bca3aa7cc0af3e2
Status affected
Version eeb386aeb5b7c8d2dae6a3ba49255d8a97803182
Version < f73db632524320d2b93bc8534be8ea875053502d
Status affected
Version eeb386aeb5b7c8d2dae6a3ba49255d8a97803182
Version < 6d554f2571e6b4db242593ba561efd6a6d1f99a9
Status affected
Version eeb386aeb5b7c8d2dae6a3ba49255d8a97803182
Version < 09548edc6114f1eb1035b30795e893204ef45b85
Status affected
Version eeb386aeb5b7c8d2dae6a3ba49255d8a97803182
Version < bf09b9d7cd7890bc3a3b7eb63d5ece15f88bfde7
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4ba8a08f5f26ed59f356a6318bca3aa7cc0af3e2
https://git.kernel.org/stable/c/f73db632524320d2b93bc8534be8ea875053502d
https://git.kernel.org/stable/c/6d554f2571e6b4db242593ba561efd6a6d1f99a9
https://git.kernel.org/stable/c/09548edc6114f1eb1035b30795e893204ef45b85
https://git.kernel.org/stable/c/bf09b9d7cd7890bc3a3b7eb63d5ece15f88bfde7