KVM: s390: pci: Reject adapter interrupt forwarding if already enabled
Summary
| CVE | CVE-2026-74515 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 13:17:56 UTC |
| Updated | 2026-08-19 17:21:08 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Reject adapter interrupt forwarding if already enabled The MPCIFC instruction doesn't allow registering adapter interrupts without first unregistering. So reject any request to enable interrupt forwarding if its already enabled for the zPCI device. This also fixes overwriting and thus leaking resources when the ioctl is called multiple times for the same device. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.001290000 probability, percentile 0.029490000 (date 2026-08-19)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc 642d2d1067f7c4d753ae0e3ba5bc98b43cfe3c70 git | Not specified |
| CNA | Linux | Linux | affected 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc 78d9648e7e960546d5b72504a0b0358cd8bb1e9d git | Not specified |
| CNA | Linux | Linux | affected 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc 6be1ff49ba81f96a6fa55915e6d920be43ac57cc git | Not specified |
| CNA | Linux | Linux | affected 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc 6837f0ae85fd54cf64c8a0c7c530bba2fae0a207 git | Not specified |
| CNA | Linux | Linux | affected 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc 591952b63a9f976da7d49f719f36ec826ee2a575 git | Not specified |
| CNA | Linux | Linux | affected 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc 8fa01be5a6149404adb82c0979a78f6347edd3ef git | Not specified |
| CNA | Linux | Linux | affected 6.0 | Not specified |
| CNA | Linux | Linux | unaffected 6.0 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.183 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.151 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.103 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.44 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.8 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/642d2d1067f7c4d753ae0e3ba5bc98b43cfe3c70 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/591952b63a9f976da7d49f719f36ec826ee2a575 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8fa01be5a6149404adb82c0979a78f6347edd3ef | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6837f0ae85fd54cf64c8a0c7c530bba2fae0a207 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/78d9648e7e960546d5b72504a0b0358cd8bb1e9d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6be1ff49ba81f96a6fa55915e6d920be43ac57cc | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.