CVE-2026-72290

high

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix GISC refcount leak on AIF enable failure kvm_s390_gisc_register() registers the guest ISC before pinning the guest interrupt forwarding pages and allocating the AISB bit. If any of the later setup steps fails, the function unwinds the pinned pages and other local state, but does not unregister the GISC reference. Add the missing kvm_s390_gisc_unregister() to the error unwind path.

References

https://git.kernel.org/stable/c/adce12bb0e0dc82d1d6f0821c9faee3145e62a6f

https://git.kernel.org/stable/c/7b69729046a4c58f4cb457184e5ac4aaa179bff4

https://git.kernel.org/stable/c/6e69317cd44a2f21f8f7a9d93eb3220e868adfa8

https://git.kernel.org/stable/c/6cd6e1c978784eec9032e2fe94a53e62b674fe3e

https://git.kernel.org/stable/c/5fb75c5272950b3ebe8bdee7abfdafd44f38313b

https://git.kernel.org/stable/c/3882224b0e714f34de91e5f28307c5d3fccfe8f8

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00215