CVE-2026-80555
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/08/2026
Última modificación:
27/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
s390/vfio_ccw: Free all memory if cp_init() fails<br />
<br />
The routine cp_free() is called to unpin/free any memory once an I/O<br />
is completed successfully, or if cp_prefetch() fails. But if cp_init()<br />
fails, and cp->initialized is not enabled, the same routine cannot be<br />
used to free all the memory.<br />
<br />
An attempt to address this exists in ccwchain_handle_ccw(), where a<br />
single call to ccwchain_free() is made for the currently-processed<br />
CCW segment. But this will leak other segments (created as a result<br />
of a Transfer in Channel) that had been allocated as part of the same<br />
channel program.<br />
<br />
Address this by performing the cleanup outside of the recursive<br />
ccwchain_handle_ccw()/ccwchain_loop_tic() logic.
Impacto
Puntuación base 3.x
7.10
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/152fcb74a26804b70909381c6acc90595a0ae1c1
- https://git.kernel.org/stable/c/17e01e342af74de12899c206dcc9ec90684703aa
- https://git.kernel.org/stable/c/276bd7ed34d56c48c65c43c0b08f2ee77029b2fa
- https://git.kernel.org/stable/c/32e3d364a7b8295120d37e6a6bd433d2de26f748
- https://git.kernel.org/stable/c/4699b54fada156534cbb39834d47fc9374d7a1f5
- https://git.kernel.org/stable/c/6a917199aaf97904f5619afe3dfdacb155b03e8c
- https://git.kernel.org/stable/c/74186c2968f8f756ac3226b545b598457c910c75
- https://git.kernel.org/stable/c/f9bcff265556796834122f95de16d52a8375206c



