CVE-2026-68454
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest AISB location instead of virt_to_phys(page_address(NULL)).
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/124a3769c43713a11a93a821b313e61ad5110cb8
- https://git.kernel.org/stable/c/3e3aa6da87d30a0064a17b836685cd43c90a3572
- https://git.kernel.org/stable/c/3ef3190e30601b2688bdc64169b938b8d7f42010
- https://git.kernel.org/stable/c/d48b9b096d11e31690c0a4988f65f21b64c01b2a
- https://git.kernel.org/stable/c/df72596278b0e22dac5ef2881e9221a3a2c4ed11
- https://git.kernel.org/stable/c/f887df91826e72b570c5e9298e66dd929f09edde
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.