GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel KVM s390 vsie: stale crypto bits let a nested guest reach a revoked crypto device

CVSS 8.8CVE-2026-80921Kernel, userspace & hypervisorcurated

Impact

When shadowing a format0 APCB from crycb 0 or 1, bits 64..255 were left at whatever the vsie page already held, so a nested guest could retain access to a crypto adapter domain that had been taken away from it. On a multi-tenant host this is a cross-tenant reach into an adapter the guest is no longer entitled to. Exposure is narrow: this is s390 (IBM Z) only and requires nested virtualization (vsie), so an x86 or ARM GPU fleet is not affected at all. Listed for completeness for operators who run KVM on Z alongside accelerator workloads.

Who can reach it

Local: a guest running a nested guest under KVM on s390 hardware with crypto adapters passed through. No remote path; requires the host to permit nested virtualization and crypto passthrough.

What to do

Take the stable kernel fix (five backport commits are linked in the record) and reboot the host; a KVM host kernel change cannot be applied without draining guests. No mitigation is documented short of disabling nested virtualization or crypto passthrough for guests.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.