{"api_version":"1","generated_at":"2026-09-21T20:53:11+00:00","cve":"CVE-2026-89922","urls":{"html":"https://cve.report/CVE-2026-89922","api":"https://cve.report/api/cve/CVE-2026-89922.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89922","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89922"},"summary":{"title":"KVM: s390: Take srcu when importing watchpoint data","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: Take srcu when importing watchpoint data\n\n__import_wp_info() backs up the original guest memory contents of a\nwatchpoint with read_guest_abs(), which is kvm_read_guest() and therefore\nresolves the memslot via __kvm_memslots(). That requires kvm->srcu (or\nkvm->slots_lock) to be held, otherwise a concurrent memslot update can\nfree the memslots array under us once its SRCU grace period has elapsed.\n\nAs this is not fast path, following lock ordering (mutex first, then\nsrcu) take the big hammer and hold the srcu for the full import.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:17:01","updated_at":"2026-09-16 15:18:18"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/f8e3a9997d5ecd56ebe4b262ff424516c068fecb","name":"https://git.kernel.org/stable/c/f8e3a9997d5ecd56ebe4b262ff424516c068fecb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/cc710ee45395efb4937e042960f791d33924e5f6","name":"https://git.kernel.org/stable/c/cc710ee45395efb4937e042960f791d33924e5f6","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03","name":"https://git.kernel.org/stable/c/76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6830fbc3724bf49c142aae69a4694f115fa9cedd","name":"https://git.kernel.org/stable/c/6830fbc3724bf49c142aae69a4694f115fa9cedd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4c05bf21d1806853e662cc19e744736a3408f155","name":"https://git.kernel.org/stable/c/4c05bf21d1806853e662cc19e744736a3408f155","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a4e482def8533ebace517d9f67f1465841b1f982","name":"https://git.kernel.org/stable/c/a4e482def8533ebace517d9f67f1465841b1f982","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89922","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89922","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 27291e2165b6de70c476b7b675308113edd69a60 6830fbc3724bf49c142aae69a4694f115fa9cedd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 27291e2165b6de70c476b7b675308113edd69a60 f8e3a9997d5ecd56ebe4b262ff424516c068fecb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 27291e2165b6de70c476b7b675308113edd69a60 76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 27291e2165b6de70c476b7b675308113edd69a60 cc710ee45395efb4937e042960f791d33924e5f6 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 27291e2165b6de70c476b7b675308113edd69a60 4c05bf21d1806853e662cc19e744736a3408f155 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 27291e2165b6de70c476b7b675308113edd69a60 a4e482def8533ebace517d9f67f1465841b1f982 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.16","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 3.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.188 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.157 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["arch/s390/kvm/kvm-s390.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"6830fbc3724bf49c142aae69a4694f115fa9cedd","status":"affected","version":"27291e2165b6de70c476b7b675308113edd69a60","versionType":"git"},{"lessThan":"f8e3a9997d5ecd56ebe4b262ff424516c068fecb","status":"affected","version":"27291e2165b6de70c476b7b675308113edd69a60","versionType":"git"},{"lessThan":"76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03","status":"affected","version":"27291e2165b6de70c476b7b675308113edd69a60","versionType":"git"},{"lessThan":"cc710ee45395efb4937e042960f791d33924e5f6","status":"affected","version":"27291e2165b6de70c476b7b675308113edd69a60","versionType":"git"},{"lessThan":"4c05bf21d1806853e662cc19e744736a3408f155","status":"affected","version":"27291e2165b6de70c476b7b675308113edd69a60","versionType":"git"},{"lessThan":"a4e482def8533ebace517d9f67f1465841b1f982","status":"affected","version":"27291e2165b6de70c476b7b675308113edd69a60","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["arch/s390/kvm/kvm-s390.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"3.16"},{"lessThan":"3.16","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.188","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.157","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.188","versionStartIncluding":"3.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.157","versionStartIncluding":"3.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"3.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"3.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"3.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"3.16","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: Take srcu when importing watchpoint data\n\n__import_wp_info() backs up the original guest memory contents of a\nwatchpoint with read_guest_abs(), which is kvm_read_guest() and therefore\nresolves the memslot via __kvm_memslots(). That requires kvm->srcu (or\nkvm->slots_lock) to be held, otherwise a concurrent memslot update can\nfree the memslots array under us once its SRCU grace period has elapsed.\n\nAs this is not fast path, following lock ordering (mutex first, then\nsrcu) take the big hammer and hold the srcu for the full import."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through the local KVM_SET_GUEST_DEBUG vCPU ioctl on a fd from /dev/kvm (kvm_vcpu_ioctl -> kvm_arch_vcpu_ioctl_set_guest_debug -> kvm_s390_import_bp_data). No network, adjacent-radio, or physical-device path reaches this s390 watchpoint import.\nAC:L - The attacker controls both sides of the race: one thread issues KVM_SET_GUEST_DEBUG with KVM_GUESTDBG_USE_HW_BP while another mutates memslots via KVM_SET_USER_MEMORY_REGION on the VM fd. Guest PER (sclp.has_gpere) is standard on s390 KVM hosts, not a rare config the attacker cannot influence.\nPR:L - The ioctl path has no capability check; only s390 ucontrol VMs require CAP_SYS_ADMIN. An unprivileged user with /dev/kvm access (kvm group or mode 0666, typical on virtualization hosts) can create a VM/vCPU and trigger the import.\nUI:N - The attacking process creates the VM and vCPU, installs hardware watchpoints, and races memslot updates itself. No separate victim user action such as mounting a filesystem or opening a file is required.\nS:U - KVM_SET_GUEST_DEBUG is a host-userspace ioctl; a guest cannot issue it, and this is not a guest-to-host escape. Impact stays within the host kernel's security authority, matching other KVM ioctl missing-SRCU UAFs.\nC:H - Without SRCU, read_guest_abs()/kvm_read_guest() resolves memslots via __kvm_memslots() while a concurrent update can kfree the kvm_memory_slot after the SRCU grace period. Use-after-free of slot metadata and gfn-tree nodes enables kernel-heap disclosure and is scored High.\nI:H - The same UAF lets the attacker reclaim the freed kvm_memory_slot, plant a dangling last_used_slot pointer, and walk attacker-controlled rb_left/rb_right during search_memslots(), yielding a kernel write/control-flow primitive. Kernel UAF memory corruption is scored High integrity.\nA:H - Dereferencing a freed kvm_memory_slot or walking a concurrently destroyed gfn rbtree causes a host kernel oops or panic. The unprotected srcu_dereference_check() also trips lockdep, which is fatal under panic_on_warn."}]}],"providerMetadata":{"dateUpdated":"2026-09-16T14:40:15.723Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/6830fbc3724bf49c142aae69a4694f115fa9cedd"},{"url":"https://git.kernel.org/stable/c/f8e3a9997d5ecd56ebe4b262ff424516c068fecb"},{"url":"https://git.kernel.org/stable/c/76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03"},{"url":"https://git.kernel.org/stable/c/cc710ee45395efb4937e042960f791d33924e5f6"},{"url":"https://git.kernel.org/stable/c/4c05bf21d1806853e662cc19e744736a3408f155"},{"url":"https://git.kernel.org/stable/c/a4e482def8533ebace517d9f67f1465841b1f982"}],"title":"KVM: s390: Take srcu when importing watchpoint data","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89922","datePublished":"2026-09-16T10:32:16.110Z","dateReserved":"2026-09-11T19:38:34.775Z","dateUpdated":"2026-09-16T14:40:15.723Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:17:01","lastModifiedDate":"2026-09-16 15:18:18","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89922","Ordinal":"1","Title":"KVM: s390: Take srcu when importing watchpoint data","CVE":"CVE-2026-89922","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89922","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: Take srcu when importing watchpoint data\n\n__import_wp_info() backs up the original guest memory contents of a\nwatchpoint with read_guest_abs(), which is kvm_read_guest() and therefore\nresolves the memslot via __kvm_memslots(). That requires kvm->srcu (or\nkvm->slots_lock) to be held, otherwise a concurrent memslot update can\nfree the memslots array under us once its SRCU grace period has elapsed.\n\nAs this is not fast path, following lock ordering (mutex first, then\nsrcu) take the big hammer and hold the srcu for the full import.","Type":"Description","Title":"KVM: s390: Take srcu when importing watchpoint data"}]}}}