{"api_version":"1","generated_at":"2026-08-27T14:57:29+00:00","cve":"CVE-2026-80549","urls":{"html":"https://cve.report/CVE-2026-80549","api":"https://cve.report/api/cve/CVE-2026-80549.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80549","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80549"},"summary":{"title":"s390/vfio_ccw: Move cp cleanup out of not operational","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Move cp cleanup out of not operational\n\nThe fsm_notoper() routine is called when the device has been\nlost, and is (by definition) no longer operational. Since this\ncan happen asynchronously from the normal behavior of the\ndriver, the cleanup may happen when holding other locks\nin the calling sequence (notably, the cio subchannel lock).\n\nPush the cleanup of the private->cp resources to a workqueue,\nwhere it can be done out from under that lock sequence and\na future patch can safely manage the locking requirements.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-26 15:17:09","updated_at":"2026-08-27 13:18:39"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.2","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.2","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/af1759d8e6e6da9ba94f30a2f92546f406899aa7","name":"https://git.kernel.org/stable/c/af1759d8e6e6da9ba94f30a2f92546f406899aa7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0c11f61a876ed6fcca53d442ed3f33ea8362a0f9","name":"https://git.kernel.org/stable/c/0c11f61a876ed6fcca53d442ed3f33ea8362a0f9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c9b85aa2cf73ea645e55e2c2670e0ddebfe1589b","name":"https://git.kernel.org/stable/c/c9b85aa2cf73ea645e55e2c2670e0ddebfe1589b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/56100baa0eb7055b1026dfa73e696e8066ff71fd","name":"https://git.kernel.org/stable/c/56100baa0eb7055b1026dfa73e696e8066ff71fd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f98a9890ca42f4223d2d4c50e0660af3e012fcb4","name":"https://git.kernel.org/stable/c/f98a9890ca42f4223d2d4c50e0660af3e012fcb4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4e3301e2a651d742c05914f6074a25b8e41bce19","name":"https://git.kernel.org/stable/c/4e3301e2a651d742c05914f6074a25b8e41bce19","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80549","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80549","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 204b394a23ad5e30944f23518e21e844614da2ff c9b85aa2cf73ea645e55e2c2670e0ddebfe1589b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 204b394a23ad5e30944f23518e21e844614da2ff f98a9890ca42f4223d2d4c50e0660af3e012fcb4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 204b394a23ad5e30944f23518e21e844614da2ff 4e3301e2a651d742c05914f6074a25b8e41bce19 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 204b394a23ad5e30944f23518e21e844614da2ff af1759d8e6e6da9ba94f30a2f92546f406899aa7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 204b394a23ad5e30944f23518e21e844614da2ff 56100baa0eb7055b1026dfa73e696e8066ff71fd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 204b394a23ad5e30944f23518e21e844614da2ff 0c11f61a876ed6fcca53d442ed3f33ea8362a0f9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.0","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.0 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.185 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.153 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.105 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.46 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.10 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/s390/cio/vfio_ccw_drv.c","drivers/s390/cio/vfio_ccw_fsm.c","drivers/s390/cio/vfio_ccw_ops.c","drivers/s390/cio/vfio_ccw_private.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"c9b85aa2cf73ea645e55e2c2670e0ddebfe1589b","status":"affected","version":"204b394a23ad5e30944f23518e21e844614da2ff","versionType":"git"},{"lessThan":"f98a9890ca42f4223d2d4c50e0660af3e012fcb4","status":"affected","version":"204b394a23ad5e30944f23518e21e844614da2ff","versionType":"git"},{"lessThan":"4e3301e2a651d742c05914f6074a25b8e41bce19","status":"affected","version":"204b394a23ad5e30944f23518e21e844614da2ff","versionType":"git"},{"lessThan":"af1759d8e6e6da9ba94f30a2f92546f406899aa7","status":"affected","version":"204b394a23ad5e30944f23518e21e844614da2ff","versionType":"git"},{"lessThan":"56100baa0eb7055b1026dfa73e696e8066ff71fd","status":"affected","version":"204b394a23ad5e30944f23518e21e844614da2ff","versionType":"git"},{"lessThan":"0c11f61a876ed6fcca53d442ed3f33ea8362a0f9","status":"affected","version":"204b394a23ad5e30944f23518e21e844614da2ff","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/s390/cio/vfio_ccw_drv.c","drivers/s390/cio/vfio_ccw_fsm.c","drivers/s390/cio/vfio_ccw_ops.c","drivers/s390/cio/vfio_ccw_private.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.0"},{"lessThan":"6.0","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.185","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.153","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.105","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.46","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.10","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.185","versionStartIncluding":"6.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.153","versionStartIncluding":"6.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.105","versionStartIncluding":"6.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.46","versionStartIncluding":"6.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.10","versionStartIncluding":"6.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"6.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Move cp cleanup out of not operational\n\nThe fsm_notoper() routine is called when the device has been\nlost, and is (by definition) no longer operational. Since this\ncan happen asynchronously from the normal behavior of the\ndriver, the cleanup may happen when holding other locks\nin the calling sequence (notably, the cio subchannel lock).\n\nPush the cleanup of the private->cp resources to a workqueue,\nwhere it can be done out from under that lock sequence and\na future patch can safely manage the locking requirements."}],"metrics":[{"cvssV3_1":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - Reachable only via local VFIO/mdev device access (pread/pwrite/ioctl on an opened vfio-ccw mediated device); the vulnerable cp_free() runs from FSM not-operational handling triggered by CIO subchannel events and VFIO I/O, not from any network protocol.\nAC:L - A VFIO client can submit channel programs and concurrently provoke not-operational transitions (device close/reset, in-flight I/O, or subchannel state changes), controlling both sides of the race without rare external timing.\nPR:H - Exploitation requires opening and operating an s390 vfio-ccw passthrough mdev, which needs host administrator setup and CAP_SYS_ADMIN-level VFIO/IOMMU access that cannot be obtained from an unprivileged user namespace.\nUI:N - No victim interaction is required beyond the attacker already having VFIO device access; triggering the bug is fully automated through concurrent I/O submissions and device state transitions.\nS:C - vfio-ccw manages guest DMA page pinning/unpinning through the IOMMU for channel I/O passthrough; unsynchronized cp_free() under the wrong locks can corrupt that isolation boundary between the VFIO guest and the host kernel.\nC:H - Concurrent unsynchronized cp_free() on an active channel_program can double-free or use-after-free kmalloc'd ccwchain/page_array metadata and pinned page state, yielding kernel memory disclosure primitives per UAF guidance.\nI:H - The same race while unpining guest pages and freeing channel-program structures can corrupt heap metadata and IOMMU mappings, enabling arbitrary kernel write or control-flow hijack per memory-corruption guidance.\nA:H - Calling sleeping vfio_unpin_pages()/cp_free() while holding the subchannel spinlock can deadlock the kernel, and the concurrent double-free/UAF reliably causes kernel oops/panic under load."}]}],"providerMetadata":{"dateUpdated":"2026-08-27T12:40:09.822Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/c9b85aa2cf73ea645e55e2c2670e0ddebfe1589b"},{"url":"https://git.kernel.org/stable/c/f98a9890ca42f4223d2d4c50e0660af3e012fcb4"},{"url":"https://git.kernel.org/stable/c/4e3301e2a651d742c05914f6074a25b8e41bce19"},{"url":"https://git.kernel.org/stable/c/af1759d8e6e6da9ba94f30a2f92546f406899aa7"},{"url":"https://git.kernel.org/stable/c/56100baa0eb7055b1026dfa73e696e8066ff71fd"},{"url":"https://git.kernel.org/stable/c/0c11f61a876ed6fcca53d442ed3f33ea8362a0f9"}],"title":"s390/vfio_ccw: Move cp cleanup out of not operational","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80549","datePublished":"2026-08-26T14:37:19.353Z","dateReserved":"2026-08-26T14:34:25.766Z","dateUpdated":"2026-08-27T12:40:09.822Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-26 15:17:09","lastModifiedDate":"2026-08-27 13:18:39","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.5,"impactScore":6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80549","Ordinal":"1","Title":"s390/vfio_ccw: Move cp cleanup out of not operational","CVE":"CVE-2026-80549","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80549","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Move cp cleanup out of not operational\n\nThe fsm_notoper() routine is called when the device has been\nlost, and is (by definition) no longer operational. Since this\ncan happen asynchronously from the normal behavior of the\ndriver, the cleanup may happen when holding other locks\nin the calling sequence (notably, the cio subchannel lock).\n\nPush the cleanup of the private->cp resources to a workqueue,\nwhere it can be done out from under that lock sequence and\na future patch can safely manage the locking requirements.","Type":"Description","Title":"s390/vfio_ccw: Move cp cleanup out of not operational"}]}}}