{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80552","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.766Z","datePublished":"2026-08-26T14:37:21.178Z","dateUpdated":"2026-08-27T12:40:12.535Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-27T12:40:12.535Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Ensure index for read/write regions are within range\n\nThe introduction of the capability chain rightly clamped the\nregion indexes to the range of the capabilities itself, but\nneglected to do so for the existing read/write regions which\nshould also be enforced."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is reached only via local VFIO mediated-device syscalls (read/write on a vfio-ccw device fd and VFIO_DEVICE_GET_REGION_INFO ioctl); vfio-ccw has no network, Bluetooth, or physical-bus entry point.\nAC:L - An attacker with an open vfio-ccw fd can deterministically supply crafted file offsets encoding out-of-range region indexes to read/write/ioctl handlers, or race close/teardown against region access, without depending on uncontrollable kernel layout or rare timing.\nPR:L - Exploitation requires an opened vfio-ccw mdev device fd (typical QEMU/libvirt VM operator or delegated /dev/vfio holder on IBM Z passthrough); mdev creation is admin setup, but triggering the OOB paths needs only that delegated VFIO client, not init-namespace root.\nUI:N - No separate victim action is required beyond the attacker (or their QEMU process) issuing crafted VFIO read/write/ioctl calls on an already-assigned passthrough device; no mount, click, or other user cooperation is needed at trigger time.\nS:C - On IBM Z/LinuxONE, vfio-ccw exists to pass DASD/CCW subchannels into KVM guests; OOB region indexing in host read/write/ioctl corrupts hypervisor kernel memory outside the guest VM security boundary, enabling cross-tenant host compromise.\nC:H - Missing bounds checks and array_index_nospec on region[i] let out-of-range indexes make copy_to_user read from adjacent kernel heap/metadata beyond the region array, providing arbitrary kernel memory disclosure primitives.\nI:H - Out-of-range region indexes route copy_from_user writes to wrong kernel objects (cmd_region, schib_region, crw_region, or adjacent heap), enabling heap corruption and exploitable arbitrary kernel write or control-flow hijack.\nA:H - Out-of-bounds access to freed or invalid region metadata during concurrent device close, or corrupting vfio_ccw_private adjacent structures, can immediately oops or panic the host kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/s390/cio/vfio_ccw_async.c","drivers/s390/cio/vfio_ccw_chp.c","drivers/s390/cio/vfio_ccw_ops.c"],"versions":[{"version":"db8e5d17ac03a65e2e0ee0ba50bf61a99741d871","lessThan":"3acbedf5c0b8e0971f0de423c05cc02bbf6ddb99","status":"affected","versionType":"git"},{"version":"db8e5d17ac03a65e2e0ee0ba50bf61a99741d871","lessThan":"d3b1e38404b22df5a1f93019f2bb656feaad5ae3","status":"affected","versionType":"git"},{"version":"db8e5d17ac03a65e2e0ee0ba50bf61a99741d871","lessThan":"79ea5e0c4c8a9842ae85f45062d947b3297dfc07","status":"affected","versionType":"git"},{"version":"db8e5d17ac03a65e2e0ee0ba50bf61a99741d871","lessThan":"d597fa1273802941c7801202135976fecc29672b","status":"affected","versionType":"git"},{"version":"db8e5d17ac03a65e2e0ee0ba50bf61a99741d871","lessThan":"649badf3a2fd8929e40198603a2cb21b74c21700","status":"affected","versionType":"git"},{"version":"db8e5d17ac03a65e2e0ee0ba50bf61a99741d871","lessThan":"988d9b5be3c2c4baf9457ce8e11b477e13eb9fcf","status":"affected","versionType":"git"},{"version":"db8e5d17ac03a65e2e0ee0ba50bf61a99741d871","lessThan":"9f5f9a78fedc45bc29d6a0a64e3a3472361afae5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/s390/cio/vfio_ccw_async.c","drivers/s390/cio/vfio_ccw_chp.c","drivers/s390/cio/vfio_ccw_ops.c"],"versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","status":"unaffected","versionType":"semver"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"5.15.218"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.1.184"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.6.153"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.12.105"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.18.46"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.1.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3acbedf5c0b8e0971f0de423c05cc02bbf6ddb99"},{"url":"https://git.kernel.org/stable/c/d3b1e38404b22df5a1f93019f2bb656feaad5ae3"},{"url":"https://git.kernel.org/stable/c/79ea5e0c4c8a9842ae85f45062d947b3297dfc07"},{"url":"https://git.kernel.org/stable/c/d597fa1273802941c7801202135976fecc29672b"},{"url":"https://git.kernel.org/stable/c/649badf3a2fd8929e40198603a2cb21b74c21700"},{"url":"https://git.kernel.org/stable/c/988d9b5be3c2c4baf9457ce8e11b477e13eb9fcf"},{"url":"https://git.kernel.org/stable/c/9f5f9a78fedc45bc29d6a0a64e3a3472361afae5"}],"title":"s390/vfio_ccw: Ensure index for read/write regions are within range","x_generator":{"engine":"bippy-1.2.0"}}}}