CVE-2026-80552
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure index for read/write regions are within range The introduction of the capability chain rightly clamped the region indexes to the range of the capabilities itself,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure index for read/write regions are within range The introduction of the capability chain rightly clamped the region indexes to the range of the capabilities itself, but neglected to do so for the existing read/write regions which should also be enforced.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/3acbedf5c0b8e0971f0de423c05cc02bbf6ddb99
- https://git.kernel.org/stable/c/649badf3a2fd8929e40198603a2cb21b74c21700
- https://git.kernel.org/stable/c/79ea5e0c4c8a9842ae85f45062d947b3297dfc07
- https://git.kernel.org/stable/c/988d9b5be3c2c4baf9457ce8e11b477e13eb9fcf
- https://git.kernel.org/stable/c/9f5f9a78fedc45bc29d6a0a64e3a3472361afae5
- https://git.kernel.org/stable/c/d3b1e38404b22df5a1f93019f2bb656feaad5ae3
- https://git.kernel.org/stable/c/d597fa1273802941c7801202135976fecc29672b
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.