GPU VulnDB

Database/Kernel, userspace & hypervisor

KVM on s390: uninitialized stack bytes in injected pfault interrupt state readable via migration ioctls

UnscoredCVE-2026-89921Kernel, userspace & hypervisorcurated

Impact

__kvm_inject_pfault_token() filled only part of an on-stack struct kvm_s390_irq, but the whole ext substructure was copied into per-CPU interrupt state, carrying stale kernel stack bytes along. Interrupt delivery only consumes ext_params2, so nothing reaches the guest; the leak is reachable by a host-side user who can call the migration ioctls on the VM and read back pending interrupt state. That is a small kernel-memory disclosure to whoever already controls the VMM process, not a guest escape or a cross-tenant read. It is s390-only, so an x86 or ARM GPU fleet is not affected at all.

Who can reach it

Local host user with access to a KVM VM's migration ioctls - in practice the VMM process itself. Guests cannot reach it. s390 hosts only.

What to do

Pick up the stable fix that zero-initializes the irq and inti structures (commits in the record). Kernel change, so a drain and reboot per affected host. For anyone not running s390 KVM there is nothing to do.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.