CVE-2026-89922
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: Take srcu when importing watchpoint data
__import_wp_info() backs up the original guest memory contents of a watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or kvm->slots_lock) to be held, otherwise a concurrent memslot update can free the memslots array under us once its SRCU grace period has elapsed.
As this is not fast path, following lock ordering (mutex first, then srcu) take the big hammer and hold the srcu for the full import.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1499.004Application or System Exploitationimpact70 % - Impacto secundario
T1565.001Stored Data Manipulationimpact65 %
Vulnerabilidad de escalada de privilegios local en KVM/s390 por race condition en gestión de SRCU. AV:L, PR:L permite T1068. Impactos: DoS por crash del hipervisor (A:H), corrupción/lectura de memoria de guest (C:H, I:H).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/4c05bf21d1806853e662cc19e744736a3408f155
- https://git.kernel.org/stable/c/6830fbc3724bf49c142aae69a4694f115fa9cedd
- https://git.kernel.org/stable/c/76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03
- https://git.kernel.org/stable/c/a4e482def8533ebace517d9f67f1465841b1f982
- https://git.kernel.org/stable/c/cc710ee45395efb4937e042960f791d33924e5f6
- https://git.kernel.org/stable/c/f8e3a9997d5ecd56ebe4b262ff424516c068fecb
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89922",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "27291e2165b6de70c476b7b675308113edd69a60",
"lessThan": "6830fbc3724bf49c142aae69a4694f115fa9cedd",
"versionType": "git"
},
{
"status": "affected",
"version": "27291e2165b6de70c476b7b675308113edd69a60",
"lessThan": "f8e3a9997d5ecd56ebe4b262ff424516c068fecb",
"versionType": "git"
},
{
"status": "affected",
"version": "27291e2165b6de70c476b7b675308113edd69a60",
"lessThan": "76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03",
"versionType": "git"
},
{
"status": "affected",
"version": "27291e2165b6de70c476b7b675308113edd69a60",
"lessThan": "cc710ee45395efb4937e042960f791d33924e5f6",
"versionType": "git"
},
{
"status": "affected",
"version": "27291e2165b6de70c476b7b675308113edd69a60",
"lessThan": "4c05bf21d1806853e662cc19e744736a3408f155",
"versionType": "git"
},
{
"status": "affected",
"version": "27291e2165b6de70c476b7b675308113edd69a60",
"lessThan": "a4e482def8533ebace517d9f67f1465841b1f982",
"versionType": "git"
}
],
"programFiles": [
"arch/s390/kvm/kvm-s390.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.16"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.16",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.51",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/s390/kvm/kvm-s390.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-16T11:17:01.277",
"references": [
{
"url": "https://git.kernel.org/stable/c/4c05bf21d1806853e662cc19e744736a3408f155",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6830fbc3724bf49c142aae69a4694f115fa9cedd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a4e482def8533ebace517d9f67f1465841b1f982",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cc710ee45395efb4937e042960f791d33924e5f6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f8e3a9997d5ecd56ebe4b262ff424516c068fecb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: Take srcu when importing watchpoint data\n\n__import_wp_info() backs up the original guest memory contents of a\nwatchpoint with read_guest_abs(), which is kvm_read_guest() and therefore\nresolves the memslot via __kvm_memslots(). That requires kvm->srcu (or\nkvm->slots_lock) to be held, otherwise a concurrent memslot update can\nfree the memslots array under us once its SRCU grace period has elapsed.\n\nAs this is not fast path, following lock ordering (mutex first, then\nsrcu) take the big hammer and hold the srcu for the full import."
}
],
"lastModified": "2026-09-16T15:18:18.357",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}