← All Advisories

CVE-2026-89921

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89921

Key Details

CVECVE-2026-89921
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Zero initialize data structures for inject_pfault_token

__kvm_inject_pfault_token() only sets .type and .u.ext.ext_params2 of

the on-stack struct kvm_s390_irq but the full ext substructure is copied

into the cpu local variable on inject. ext_params and pad contain stale

stack values.

Interrupt delivery only uses ext_params2, so nothing leaks to the guest,

but a host user can use the migration ioctls to get to the data.

Fix by zero-initializing the irq struct.

Do the same for the inti data structure. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89921
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89921