s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap
Summary
| CVE | CVE-2026-93238 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-24 16:17:19 UTC |
| Updated | 2026-09-24 16:17:19 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap
The DECLARE_BITMAP(apm_filtered, AP_DEVICES) macro allocates the bitmap
on the stack without zero-initializing it.
In vfio_ap_mdev_hot_plug_cfg(), the vfio_ap_mdev_filter_matrix() function
is only called to initialize and populate apm_filtered if either
filter_adapters or filter_domains is true. If the hot plug configuration
change only adds control domains (meaning filter_cdoms is true, but
filter_adapters and filter_domains are both false),
vfio_ap_mdev_filter_matrix() is bypassed.
Consequently, apm_filtered is passed to reset_queues_for_apids() with
uninitialized stack garbage. This can cause reset_queues_for_apids() to
interpret arbitrary stack garbage bits as valid APIDs to reset, potentially
performing unintended guest hardware queue resets.
Fix this by zero-initializing the apm_filtered bitmap at the beginning of
vfio_ap_mdev_hot_plug_cfg() using bitmap_zero(). |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected eeb386aeb5b7c8d2dae6a3ba49255d8a97803182 4ba8a08f5f26ed59f356a6318bca3aa7cc0af3e2 git |
Not specified |
| CNA |
Linux |
Linux |
affected eeb386aeb5b7c8d2dae6a3ba49255d8a97803182 f73db632524320d2b93bc8534be8ea875053502d git |
Not specified |
| CNA |
Linux |
Linux |
affected eeb386aeb5b7c8d2dae6a3ba49255d8a97803182 6d554f2571e6b4db242593ba561efd6a6d1f99a9 git |
Not specified |
| CNA |
Linux |
Linux |
affected eeb386aeb5b7c8d2dae6a3ba49255d8a97803182 09548edc6114f1eb1035b30795e893204ef45b85 git |
Not specified |
| CNA |
Linux |
Linux |
affected eeb386aeb5b7c8d2dae6a3ba49255d8a97803182 bf09b9d7cd7890bc3a3b7eb63d5ece15f88bfde7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.0 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.0 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.157 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.51 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.5 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/6d554f2571e6b4db242593ba561efd6a6d1f99a9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/bf09b9d7cd7890bc3a3b7eb63d5ece15f88bfde7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f73db632524320d2b93bc8534be8ea875053502d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/09548edc6114f1eb1035b30795e893204ef45b85 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/4ba8a08f5f26ed59f356a6318bca3aa7cc0af3e2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.