« Volver al listado

CVE-2026-89955

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

s390/vfio-ap: Fix NULL deref in status_show() during queue probe

When vfio_ap_mdev_probe_queue() creates the sysfs attribute group, the queue's driver data has not yet been set. A concurrent read of the 'status' attribute can therefore call dev_get_drvdata() and get NULL, which is then passed directly to vfio_ap_mdev_for_queue() where q->apqn is unconditionally dereferenced, causing a NULL pointer dereference.

Fix this by acquiring the update locks before calling sysfs_create_group(). The status_show() function acquires guests_lock before reading the driver data, so any concurrent read will block until after dev_set_drvdata() has been called and the update locks are released.

Leer descripción completaMostrar menos

As a bonus, the APQN no longer needs to be read from the queue struct after allocation — it can be read directly from apdev before allocation and stored in a local variable, which is then assigned to q->apqn once the allocation succeeds.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89955",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "260f3ea141382386e97611e7c2029bc013088ab1",
              "lessThan": "31fa0a8a3c337ed2d200166d6926ab23c14f8b2e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "260f3ea141382386e97611e7c2029bc013088ab1",
              "lessThan": "e102ce0f4af99dff769a4b1b4daa4cc6bd5ad2d9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "260f3ea141382386e97611e7c2029bc013088ab1",
              "lessThan": "69632952aca04caa71e49953b6949fc04e788e67",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "260f3ea141382386e97611e7c2029bc013088ab1",
              "lessThan": "7db2511fc601ca3a6e3fb1bdce02261c3c3167c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "260f3ea141382386e97611e7c2029bc013088ab1",
              "lessThan": "dd6f4ef6f8a37412909ad787c837332fb070159c",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/s390/crypto/vfio_ap_ops.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/s390/crypto/vfio_ap_ops.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:05.797",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/31fa0a8a3c337ed2d200166d6926ab23c14f8b2e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/69632952aca04caa71e49953b6949fc04e788e67",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7db2511fc601ca3a6e3fb1bdce02261c3c3167c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dd6f4ef6f8a37412909ad787c837332fb070159c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e102ce0f4af99dff769a4b1b4daa4cc6bd5ad2d9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio-ap: Fix NULL deref in status_show() during queue probe\n\nWhen vfio_ap_mdev_probe_queue() creates the sysfs attribute group,\nthe queue's driver data has not yet been set. A concurrent read of\nthe 'status' attribute can therefore call dev_get_drvdata() and\nget NULL, which is then passed directly to\nvfio_ap_mdev_for_queue() where q->apqn is unconditionally\ndereferenced, causing a NULL pointer dereference.\n\nFix this by acquiring the update locks before calling\nsysfs_create_group(). The status_show() function acquires\nguests_lock before reading the driver data, so any concurrent\nread will block until after dev_set_drvdata() has been called\nand the update locks are released.\n\nAs a bonus, the APQN no longer needs to be read from the queue\nstruct after allocation — it can be read directly from apdev\nbefore allocation and stored in a local variable, which is then\nassigned to q->apqn once the allocation succeeds."
    }
  ],
  "lastModified": "2026-09-16T11:17:05.797",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}