Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-97593

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX<br /> <br /> When using a 5-level translation table via ZPCI_TABLE_TYPE_RFX<br /> get_rso_from_iova() returns NULL when the region-first entry is invalid.<br /> Yet in get_rto_from_iova() the region-second origin rso is not checked<br /> to be non-NULL before accessing rso[rsx] leading to a NULL pointer<br /> dereference instead of a NULL return when iova_to_phys() is called on<br /> a unmapped IOVA. Fix this by adding the missing NULL check.

Impacto