CVE-2026-80554
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/08/2026
Última modificación:
27/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
s390/vfio_ccw: Limit the number of channel program segments<br />
<br />
The processing of channel programs, and the CCWs within them, is done<br />
recursively. As such, there is an arbitrary (but not architectural)<br />
limit to the number of CCWs that can exist in a single channel program.<br />
<br />
The vfio-ccw logic breaks these channel programs into segments whenever<br />
it encounters a Transfer-In-Channel (TIC) CCW, and the combined number<br />
of segments count towards the global limit. Impose an equivalent limit<br />
to the number of segments until such logic can be made non-recursive.
Impacto
Puntuación base 3.x
9.30
Gravedad 3.x
CRÍTICA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/06f4d6e5a8af6c2072e8cd39dbc512c683ca7fb2
- https://git.kernel.org/stable/c/15fb4559a7fdf0b8725e433a71cfd03a1313a48b
- https://git.kernel.org/stable/c/4ee94790490ae8dcc97df8597f07836c8a81bbcf
- https://git.kernel.org/stable/c/5405c90d6a47b3014e74ee0618a162449abbbc93
- https://git.kernel.org/stable/c/a1625f66eaa1200068a0e2c05bc90e65182fc4e3



