{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89955","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.777Z","datePublished":"2026-09-16T10:32:39.064Z","dateUpdated":"2026-09-16T10:32:39.064Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T10:32:39.064Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio-ap: Fix NULL deref in status_show() during queue probe\n\nWhen vfio_ap_mdev_probe_queue() creates the sysfs attribute group,\nthe queue's driver data has not yet been set. A concurrent read of\nthe 'status' attribute can therefore call dev_get_drvdata() and\nget NULL, which is then passed directly to\nvfio_ap_mdev_for_queue() where q->apqn is unconditionally\ndereferenced, causing a NULL pointer dereference.\n\nFix this by acquiring the update locks before calling\nsysfs_create_group(). The status_show() function acquires\nguests_lock before reading the driver data, so any concurrent\nread will block until after dev_set_drvdata() has been called\nand the update locks are released.\n\nAs a bonus, the APQN no longer needs to be read from the queue\nstruct after allocation — it can be read directly from apdev\nbefore allocation and stored in a local variable, which is then\nassigned to q->apqn once the allocation succeeds."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/s390/crypto/vfio_ap_ops.c"],"versions":[{"version":"260f3ea141382386e97611e7c2029bc013088ab1","lessThan":"31fa0a8a3c337ed2d200166d6926ab23c14f8b2e","status":"affected","versionType":"git"},{"version":"260f3ea141382386e97611e7c2029bc013088ab1","lessThan":"e102ce0f4af99dff769a4b1b4daa4cc6bd5ad2d9","status":"affected","versionType":"git"},{"version":"260f3ea141382386e97611e7c2029bc013088ab1","lessThan":"69632952aca04caa71e49953b6949fc04e788e67","status":"affected","versionType":"git"},{"version":"260f3ea141382386e97611e7c2029bc013088ab1","lessThan":"7db2511fc601ca3a6e3fb1bdce02261c3c3167c3","status":"affected","versionType":"git"},{"version":"260f3ea141382386e97611e7c2029bc013088ab1","lessThan":"dd6f4ef6f8a37412909ad787c837332fb070159c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/s390/crypto/vfio_ap_ops.c"],"versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/31fa0a8a3c337ed2d200166d6926ab23c14f8b2e"},{"url":"https://git.kernel.org/stable/c/e102ce0f4af99dff769a4b1b4daa4cc6bd5ad2d9"},{"url":"https://git.kernel.org/stable/c/69632952aca04caa71e49953b6949fc04e788e67"},{"url":"https://git.kernel.org/stable/c/7db2511fc601ca3a6e3fb1bdce02261c3c3167c3"},{"url":"https://git.kernel.org/stable/c/dd6f4ef6f8a37412909ad787c837332fb070159c"}],"title":"s390/vfio-ap: Fix NULL deref in status_show() during queue probe","x_generator":{"engine":"bippy-1.2.0"}}}}