CVE-2026-80555
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/08/2026
Last modified:
26/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
s390/vfio_ccw: Free all memory if cp_init() fails<br />
<br />
The routine cp_free() is called to unpin/free any memory once an I/O<br />
is completed successfully, or if cp_prefetch() fails. But if cp_init()<br />
fails, and cp->initialized is not enabled, the same routine cannot be<br />
used to free all the memory.<br />
<br />
An attempt to address this exists in ccwchain_handle_ccw(), where a<br />
single call to ccwchain_free() is made for the currently-processed<br />
CCW segment. But this will leak other segments (created as a result<br />
of a Transfer in Channel) that had been allocated as part of the same<br />
channel program.<br />
<br />
Address this by performing the cleanup outside of the recursive<br />
ccwchain_handle_ccw()/ccwchain_loop_tic() logic.



