CVE-2026-89922

high

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when importing watchpoint data __import_wp_info() backs up the original guest memory contents of a watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or kvm->slots_lock) to be held, otherwise a concurrent memslot update can free the memslots array under us once its SRCU grace period has elapsed. As this is not fast path, following lock ordering (mutex first, then srcu) take the big hammer and hold the srcu for the full import.

References

https://git.kernel.org/stable/c/f8e3a9997d5ecd56ebe4b262ff424516c068fecb

https://git.kernel.org/stable/c/cc710ee45395efb4937e042960f791d33924e5f6

https://git.kernel.org/stable/c/a4e482def8533ebace517d9f67f1465841b1f982

https://git.kernel.org/stable/c/76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03

https://git.kernel.org/stable/c/6830fbc3724bf49c142aae69a4694f115fa9cedd

https://git.kernel.org/stable/c/4c05bf21d1806853e662cc19e744736a3408f155

Details

Source: Mitre, NVD

Published: 2026-09-16

Updated: 2026-09-16

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00164