{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89459","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.707Z","datePublished":"2026-09-11T19:43:22.007Z","dateUpdated":"2026-09-13T06:29:33.766Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:29:33.766Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/percpu: Fix MVIY_PERCPU() with older binutils\n\nCommit a737737cdb9c (\"s390/percpu: Infrastructure for more efficient\nthis_cpu operations\") introduced MVIY_PERCPU(), which stringifies\narguments that are already C string literals. This generates an\nassembler macro invocation with whitespace-separated quoted arguments:\n\n  GEN_MVIY \"459712\" \"%r3\"\n\nGNU as versions prior to binutils 2.39 drop the separating whitespace\nbetween quoted macro arguments during input scrubbing. They\nconsequently parse the invocation as a single argument and emit\nrepeated warnings:\n\n  Warning: missing closing `\"'\n\nThe .ifc in GEN_MVIY never matches and GNU as exits successfully\nwithout emitting the mviy instruction. As a result, the interrupted\nper-CPU sequence is not marked in lowcore and the exception return\npath cannot repair the per-CPU address register after migration.\n\nAll MVIY_PERCPU() callers pass C string literals. Use them directly\nand separate the assembler macro arguments with an explicit comma. The\nresulting invocation is:\n\n  GEN_MVIY 459712, %r3\n\nThis form is unambiguous for GNU as and LLVM's integrated assembler.\nThis behavior was fixed in GNU as from binutils 2.39, but Linux\nsupports binutils 2.30."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The omitted mviy start marker is in s390 this_cpu_read/write/add sequences reached from local syscalls (mm/swap, memcg, vmalloc) and user-namespace nftables; this is an arch per-CPU primitive, not a packet parser, ksmbd/nfsd handler, or USB path.\nAC:H - The op is wrong only if an interrupt or preemption and a CPU migration both occur after AG adds the old CPU offset and before the atomic instruction; that one-instruction window is not attacker-timed, even with affinity bouncing on default PREEMPT_LAZY s390.\nPR:L - Any unprivileged local user can drive this_cpu_* via ordinary syscalls, and nft_ct's this_cpu_read(nft_ct_pcpu_template) is reachable with CAP_NET_ADMIN in a user namespace; init-namespace root is not required.\nUI:N - The attacker triggers the unmarked this_cpu sequences from their own process (syscalls or locally generated packets); no victim mount, file open, or other interaction is required.\nS:U - Stale per-CPU pointers are used inside the same host kernel after migration; this is not a KVM/Xen guest-to-host escape or IOMMU/DMA boundary bypass.\nC:H - After migration, this_cpu_read uses another CPU's pointer-typed slots (percpu_swap_cluster.si, nft_ct_pcpu_template, page-pool/socket pointers) without that CPU's locking, which can disclose kernel objects and is memory corruption leverageable for info disclosure.\nI:H - The matching this_cpu_write/add then mutates the previous CPU's per-CPU state (swap cluster cache, conntrack templates, other CPU-local structures that assume exclusive access), which is kernel memory corruption exploitable toward control-flow hijack.\nA:H - A stale per-CPU pointer after migration can oops or panic (NULL vmalloc ne_fit_preload_node, inconsistent swap_info, conntrack refcount UAF), which is a full kernel availability loss on SMP s390."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/s390/include/asm/percpu.h"],"versions":[{"version":"a737737cdb9c94e40a9926cdc2320f874c05d709","lessThan":"91770b08a120967077ae78600612f18bc5ee3caf","status":"affected","versionType":"git"},{"version":"a737737cdb9c94e40a9926cdc2320f874c05d709","lessThan":"101782f8945a125044347312d74d488c05741c4a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/s390/include/asm/percpu.h"],"versions":[{"version":"7.2","status":"affected"},{"version":"0","lessThan":"7.2","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/91770b08a120967077ae78600612f18bc5ee3caf"},{"url":"https://git.kernel.org/stable/c/101782f8945a125044347312d74d488c05741c4a"}],"title":"s390/percpu: Fix MVIY_PERCPU() with older binutils","x_generator":{"engine":"bippy-1.2.0"}}}}