CVE-2026-89924 PUBLISHED

KVM: s390: Fix old_data leak in guest debug error path

Assigner: Linux
Reserved: 11.09.2026 Published: 16.09.2026 Updated: 16.09.2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Fix old_data leak in guest debug error path

__import_wp_info() allocates a per-watchpoint old_data buffer to back up the original guest memory contents. If a later watchpoint of the same KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data() jumps to the error label, which frees the wp_info array but not the old_data buffers of the entries that were imported successfully. Up to MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed request, and the request can be repeated.

Create error handling for cleaning up all created old_data memory areas.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 27291e2165b6de70c476b7b675308113edd69a60 to 124c81ee610e1fbdd93d4399f88d9e28ba97a941 (excl.)
  • affected from 27291e2165b6de70c476b7b675308113edd69a60 to e5ae7816e5ad145618f7fd568a0e8a94dd9f81f4 (excl.)
  • affected from 27291e2165b6de70c476b7b675308113edd69a60 to c85d402553987777cc4742751437ea5dcbf98a7b (excl.)
  • affected from 27291e2165b6de70c476b7b675308113edd69a60 to 5fbf319137735252eefa507193c9a619af5b7457 (excl.)
  • affected from 27291e2165b6de70c476b7b675308113edd69a60 to 4048d0a252163084794be3e37995b872c5178913 (excl.)
  • affected from 27291e2165b6de70c476b7b675308113edd69a60 to f55e4d415d95342d5753e528e05a1e8623992c3f (excl.)
  • affected from 27291e2165b6de70c476b7b675308113edd69a60 to 46cb8a273e2f853f89a78b59dbdff8787b6e1c86 (excl.)
  • affected from 27291e2165b6de70c476b7b675308113edd69a60 to aa9c8e8baf1e765fa65b93212522c636f25d846f (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.16 is affected
  • unaffected from 0 to 3.16 (excl.)
  • unaffected from 5.10.270 to 5.10.* (incl.)
  • unaffected from 5.15.221 to 5.15.* (incl.)
  • unaffected from 6.1.188 to 6.1.* (incl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.51 to 6.18.* (incl.)
  • unaffected from 7.2.5 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References