KVM: s390: Fix memory leak in guest debug handling

Summary

CVECVE-2026-89925
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-16 11:17:01 UTC
Updated2026-09-16 11:17:01 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix memory leak in guest debug handling bp_data is freed only for the error case by kfree(bp_data). Every successful KVM_SET_GUEST_DEBUG will leak bp_data.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 27291e2165b6de70c476b7b675308113edd69a60 39e7cebb889839b5762c9ad22e2d715b5883b288 git Not specified
CNA Linux Linux affected 27291e2165b6de70c476b7b675308113edd69a60 58b1b729a9f90c80b508fc3e2174cbc0ee50859e git Not specified
CNA Linux Linux affected 27291e2165b6de70c476b7b675308113edd69a60 9071f75cbde3bf46119cb28e92cfbef830c4bf97 git Not specified
CNA Linux Linux affected 27291e2165b6de70c476b7b675308113edd69a60 5940418e4232a2ff1d30ba12e0d213dbf48f0a83 git Not specified
CNA Linux Linux affected 27291e2165b6de70c476b7b675308113edd69a60 fc2034c431adcbaabf5f8a01912358f07355349e git Not specified
CNA Linux Linux affected 27291e2165b6de70c476b7b675308113edd69a60 44bf3792c10f4bb3de507391f1837e020d92eaa2 git Not specified
CNA Linux Linux affected 27291e2165b6de70c476b7b675308113edd69a60 581be9f6085834188cef1ad2f07babf3b421e409 git Not specified
CNA Linux Linux affected 27291e2165b6de70c476b7b675308113edd69a60 121ea1de927c8b9bfdf53c31cad27b86d5de0293 git Not specified
CNA Linux Linux affected 3.16 Not specified
CNA Linux Linux unaffected 3.16 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.51 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.5 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/39e7cebb889839b5762c9ad22e2d715b5883b288 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/5940418e4232a2ff1d30ba12e0d213dbf48f0a83 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/9071f75cbde3bf46119cb28e92cfbef830c4bf97 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/581be9f6085834188cef1ad2f07babf3b421e409 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/121ea1de927c8b9bfdf53c31cad27b86d5de0293 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/44bf3792c10f4bb3de507391f1837e020d92eaa2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/58b1b729a9f90c80b508fc3e2174cbc0ee50859e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fc2034c431adcbaabf5f8a01912358f07355349e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report