{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74515","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.910Z","datePublished":"2026-08-15T12:27:35.567Z","dateUpdated":"2026-08-19T16:38:14.487Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:38:14.487Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Reject adapter interrupt forwarding if already enabled\n\nThe MPCIFC instruction doesn't allow registering adapter interrupts without\nfirst unregistering. So reject any request to enable interrupt forwarding\nif its already enabled for the zPCI device. This also fixes overwriting and\nthus leaking resources when the ioctl is called multiple times for the same\ndevice."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through the KVM_S390_ZPCI_OP VM ioctl in arch/s390/kvm/kvm-s390.c; on IBM Z with zPCI passthrough, QEMU forwards guest mpcifc adapter-interrupt registration to this local ioctl path, not over the network.\nAC:L - An attacker with an assigned zPCI device can call KVM_S390_ZPCIOP_REG_AEN twice in a row without racing or special memory layout; each duplicate call deterministically re-enters kvm_s390_pci_aif_enable() and overwrites host bookkeeping.\nPR:L - Exploitation requires a KVM VM file descriptor and a VFIO-assigned zPCI device, i.e. control of the guest/VMM process (typical cloud tenant or qemu user), not init-namespace root; this cannot be reached from an unprivileged user namespace alone.\nUI:N - Once zPCI passthrough is configured, the guest or its VMM can issue duplicate registration on its own; no additional host administrator or victim user action is needed beyond normal device setup.\nS:C - A guest-triggered ioctl corrupts host-owned AIFT/GAITE state outside the VM security boundary, leaving orphaned summary-index entries that the host interrupt path later dereferences in hypervisor context.\nC:H - Duplicate enable overwrites zdev->aisb and leaks earlier GAITE/AIBV resources; on teardown aift->kzdev[orphaned_si] still points at freed kvm_zdev/kvm, so aen_host_forward() performs UAF reads of host hypervisor memory.\nI:H - Stale orphaned GAITE entries retain guest-chosen physical addresses and dangling kzdev pointers; aen_host_forward() can execute set_bit_inv() and further host-side writes through those corrupted structures during adapter-event delivery.\nA:H - Each duplicate REG_AEN leaks pinned guest pages, AIBV allocations, and summary bits without rollback when MPCIFC re-registration fails, enabling repeatable host memory exhaustion and kernel oops/panic via IRQ-time UAF dereferences."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/s390/kvm/pci.c"],"versions":[{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"642d2d1067f7c4d753ae0e3ba5bc98b43cfe3c70","status":"affected","versionType":"git"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"78d9648e7e960546d5b72504a0b0358cd8bb1e9d","status":"affected","versionType":"git"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"6be1ff49ba81f96a6fa55915e6d920be43ac57cc","status":"affected","versionType":"git"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"6837f0ae85fd54cf64c8a0c7c530bba2fae0a207","status":"affected","versionType":"git"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"591952b63a9f976da7d49f719f36ec826ee2a575","status":"affected","versionType":"git"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"8fa01be5a6149404adb82c0979a78f6347edd3ef","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/s390/kvm/pci.c"],"versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.6.151"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.12.103"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.18.44"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.1.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/642d2d1067f7c4d753ae0e3ba5bc98b43cfe3c70"},{"url":"https://git.kernel.org/stable/c/78d9648e7e960546d5b72504a0b0358cd8bb1e9d"},{"url":"https://git.kernel.org/stable/c/6be1ff49ba81f96a6fa55915e6d920be43ac57cc"},{"url":"https://git.kernel.org/stable/c/6837f0ae85fd54cf64c8a0c7c530bba2fae0a207"},{"url":"https://git.kernel.org/stable/c/591952b63a9f976da7d49f719f36ec826ee2a575"},{"url":"https://git.kernel.org/stable/c/8fa01be5a6149404adb82c0979a78f6347edd3ef"}],"title":"KVM: s390: pci: Reject adapter interrupt forwarding if already enabled","x_generator":{"engine":"bippy-1.2.0"}}}}