CVE-2026-89922

Summary

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Take srcu when importing watchpoint data

__import_wp_info() backs up the original guest memory contents of a watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or kvm->slots_lock) to be held, otherwise a concurrent memslot update can free the memslots array under us once its SRCU grace period has elapsed.

As this is not fast path, following lock ordering (mutex first, then srcu) take the big hammer and hold the srcu for the full import.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux27291e2165b6de70c476b7b675308113edd69a60 < 6830fbc3724bf49c142aae69a4694f115fa9ceddaffected
LinuxLinux27291e2165b6de70c476b7b675308113edd69a60 < f8e3a9997d5ecd56ebe4b262ff424516c068fecbaffected
LinuxLinux27291e2165b6de70c476b7b675308113edd69a60 < 76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03affected
LinuxLinux27291e2165b6de70c476b7b675308113edd69a60 < cc710ee45395efb4937e042960f791d33924e5f6affected
LinuxLinux27291e2165b6de70c476b7b675308113edd69a60 < 4c05bf21d1806853e662cc19e744736a3408f155affected
LinuxLinux27291e2165b6de70c476b7b675308113edd69a60 < a4e482def8533ebace517d9f67f1465841b1f982affected
LinuxLinux3.16affected
LinuxLinux0 < 3.16unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References