« Volver al listado

CVE-2026-89926

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Fix length check __import_wp_info()

struct kvm_hw_breakpoint::len is a __u64 that is fully controlled by user space. This is then assigned to wp_info->len, which is an int. The bounds check is done on the truncated value while the allocation uses the untruncated one:

Use the validated value for the allocation as intended. Without this fix userspace can trigger >4GB allocations which will fail and result in a WARN due to MAX_PAGE_ORDER.

Detalles técnicos trazas, registros y código del informe original
	wp_info->len = bp_data->len;
	[...]
	if (wp_info->len < 0 || wp_info->len > MAX_WP_SIZE)
		return -EINVAL;

	wp_info->old_data = kmalloc(bp_data->len, GFP_KERNEL_ACCOUNT);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89926",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "27291e2165b6de70c476b7b675308113edd69a60",
              "lessThan": "aef540194effd768bed0bd2e6a74fe135a3d7c3a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "27291e2165b6de70c476b7b675308113edd69a60",
              "lessThan": "71153d3262517e1c02c3a66aa5094f279b2d1454",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "27291e2165b6de70c476b7b675308113edd69a60",
              "lessThan": "fec89d327d9b2b669b5bbdac209386c6317c3722",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "27291e2165b6de70c476b7b675308113edd69a60",
              "lessThan": "b94ab9caa5d72c78226121cccff5e33f946da900",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "27291e2165b6de70c476b7b675308113edd69a60",
              "lessThan": "beb9c55af609c4c7308259d7191688c75a4e3d4a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "27291e2165b6de70c476b7b675308113edd69a60",
              "lessThan": "3fe801db90bdeefb0bbdda42d832846b53f64f8a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "27291e2165b6de70c476b7b675308113edd69a60",
              "lessThan": "4c07680a467e2f7697245bcd11691bffb2a6f0ed",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "arch/s390/kvm/guestdbg.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/s390/kvm/guestdbg.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:01.777",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3fe801db90bdeefb0bbdda42d832846b53f64f8a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4c07680a467e2f7697245bcd11691bffb2a6f0ed",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/71153d3262517e1c02c3a66aa5094f279b2d1454",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aef540194effd768bed0bd2e6a74fe135a3d7c3a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b94ab9caa5d72c78226121cccff5e33f946da900",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/beb9c55af609c4c7308259d7191688c75a4e3d4a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fec89d327d9b2b669b5bbdac209386c6317c3722",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: Fix length check __import_wp_info()\n\nstruct kvm_hw_breakpoint::len is a __u64 that is fully controlled by user\nspace. This is then assigned to wp_info->len, which is an int. The bounds\ncheck is done on the truncated value while the allocation uses the\nuntruncated one:\n\n\twp_info->len = bp_data->len;\n\t[...]\n\tif (wp_info->len < 0 || wp_info->len > MAX_WP_SIZE)\n\t\treturn -EINVAL;\n\n\twp_info->old_data = kmalloc(bp_data->len, GFP_KERNEL_ACCOUNT);\n\nUse the validated value for the allocation as intended. Without this\nfix userspace can trigger >4GB allocations which will fail and result\nin a WARN due to MAX_PAGE_ORDER."
    }
  ],
  "lastModified": "2026-09-16T11:17:01.777",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}