CVE-2026-80551

critical

Description

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure first IDAW remains constant The first IDAW in a list does not need to be on a 2K/4K boundary like all others, and so is read separately to accurately calculate the size of the buffer needed to read the full IDAL. Verify that the address found in the first IDAW is unchanged between reads, to ensure a consistent set of IDAWs being worked with.

References

https://git.kernel.org/stable/c/fc59e9482117ebdccd6dc7fa8082f8b980fd021e

https://git.kernel.org/stable/c/565bef268d75bf7df665bce6923a88cd0eb74592

https://git.kernel.org/stable/c/460b977a4e71cc319fdadf91c193ec3beaa57263

https://git.kernel.org/stable/c/0d46c2565f173bcddcdcaf44a4f69789a20535e2

https://git.kernel.org/stable/c/08ef2a82115690d6e229615872ac1731af732497

Details

Source: Mitre, NVD

Published: 2026-08-26

Updated: 2026-08-27

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.3

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00144