๐Ÿ” CVE Alert

CVE-2026-89921

UNKNOWN 0.0

KVM: s390: Zero initialize data structures for inject_pfault_token

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Zero initialize data structures for inject_pfault_token __kvm_inject_pfault_token() only sets .type and .u.ext.ext_params2 of the on-stack struct kvm_s390_irq but the full ext substructure is copied into the cpu local variable on inject. ext_params and pad contain stale stack values. Interrupt delivery only uses ext_params2, so nothing leaks to the guest, but a host user can use the migration ioctls to get to the data. Fix by zero-initializing the irq struct. Do the same for the inti data structure.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
383d0b050106abecb82f43101cac94fa423af5cd < 9b046de62b8098af6e2ba820b125ec9dc5f162c8 383d0b050106abecb82f43101cac94fa423af5cd < 134f235e0e8de54611a72d3cc3f63e5f31246baa 383d0b050106abecb82f43101cac94fa423af5cd < 4e2c7f7cbc27418f9a290399b986c1b85ff93b90
Linux / Linux
3.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/9b046de62b8098af6e2ba820b125ec9dc5f162c8 git.kernel.org: https://git.kernel.org/stable/c/134f235e0e8de54611a72d3cc3f63e5f31246baa git.kernel.org: https://git.kernel.org/stable/c/4e2c7f7cbc27418f9a290399b986c1b85ff93b90