Database/Kernel, userspace & hypervisor

KVM on s390: uninitialized stack bytes in injected pfault interrupt state readable via migration ioctls
Impact
__kvm_inject_pfault_token() filled only part of an on-stack struct kvm_s390_irq, but the whole ext substructure was copied into per-CPU interrupt state, carrying stale kernel stack bytes along. Interrupt delivery only consumes ext_params2, so nothing reaches the guest; the leak is reachable by a host-side user who can call the migration ioctls on the VM and read back pending interrupt state. That is a small kernel-memory disclosure to whoever already controls the VMM process, not a guest escape or a cross-tenant read. It is s390-only, so an x86 or ARM GPU fleet is not affected at all.
Who can reach it
Local host user with access to a KVM VM's migration ioctls - in practice the VMM process itself. Guests cannot reach it. s390 hosts only.
What to do
Pick up the stable fix that zero-initializes the irq and inti structures (commits in the record). Kernel change, so a drain and reboot per affected host. For anyone not running s390 KVM there is nothing to do.
References
Related entries
- Linux kernel dma-heap: failed copy_to_user leaks an already-installed dma-buf fd for process lifetimeCVE-2026-89996 · Linux kernel dma-buf dma-heap (DMA_HEAP_IOCTL_ALLOC)Unscored
- Linux kernel arm-smmu-v3: device teardown frees the IOPF queue before the IRQ handler that uses itCVE-2026-93205 · Linux kernel iommu/arm-smmu-v3 (teardown ordering in arm_smmu_device_remove)Unscored
- Linux kernel PCI/proc: config space read checked against the reader's credentials, not the opener'sCVE-2026-93206 · Linux kernel PCI procfs interface (proc_bus_pci_read CAP_SYS_ADMIN check)Unscored
- Linux kernel SCSI core: blocking tag allocation during error recovery can deadlock the EH threadCVE-2026-93781 · Linux kernel SCSI core (scsi_eh_lock_door tag allocation)Unscored
- Linux kernel BPF: sysctl value replaced by a BPF program is not NUL-terminated, giving out-of-bounds readsCVE-2026-97420 · Linux kernel BPF (bpf_sysctl_set_new_value replacement buffer)Unscored
- Linux kernel net/rds: unprivileged container reads every RDS socket and connection on the hostCVE-2026-97476 · Linux kernel net/rds RDS_INFO_* getsockopt (missing netns filtering)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.