CVE-2026-80553
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Cancel existing workqueues
The initialization of the io_work and crw_work workqueues begs the question of whether they should be un-initialized. Add the corresponding cleanup tags in _release_dev to ensure work isn't dispatched after the private struct is free'd.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | e5f84dbaea59b4f712dac428c337528b70e1c533 < e868ea8be0bc88c6982f48ecf3259d98afd884ae | affected |
| Linux | Linux | e5f84dbaea59b4f712dac428c337528b70e1c533 < dc47a98abe6714577a25224534dbd356051097a3 | affected |
| Linux | Linux | e5f84dbaea59b4f712dac428c337528b70e1c533 < b7ae0f7993867d009a4b554fc1d6d451c10580a0 | affected |
| Linux | Linux | e5f84dbaea59b4f712dac428c337528b70e1c533 < 77f5e888d2e607a0b3141fb95091ad6ef1cca9a2 | affected |
| Linux | Linux | e5f84dbaea59b4f712dac428c337528b70e1c533 < 79c60b2c61105368dcc8444eb45847e21734f7c4 | affected |
| Linux | Linux | 4.12 | affected |
| Linux | Linux | 0 < 4.12 | unaffected |
| Linux | Linux | 6.6.153 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.105 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.46 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.10 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/e868ea8be0bc88c6982f48ecf3259d98afd884ae
- https://git.kernel.org/stable/c/dc47a98abe6714577a25224534dbd356051097a3
- https://git.kernel.org/stable/c/b7ae0f7993867d009a4b554fc1d6d451c10580a0
- https://git.kernel.org/stable/c/77f5e888d2e607a0b3141fb95091ad6ef1cca9a2
- https://git.kernel.org/stable/c/79c60b2c61105368dcc8444eb45847e21734f7c4
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.