In the Linux kernel, the following vulnerability has been resolved:
s390/vfioccw: Selectively expand iomutex
The iomutex was defined to serialize the ioregions, but then has also sort of been associated with the I/O themselves because of the close relationship they share.
With the handful of races that are possible, the choices are either to: A) expand the scope of iomutex to close these remaining windows, or B) reduce the scope of iomutex to just io_region, and introduce a new lock mechanism for the remaining I/O resources
This patch implements A, since B brings with it a lot more interactions that would need to be tracked and kept in a correct hierarchy. It also takes advantage of the workqueue element for cpfree() that now gets called out of fsmnotoper(), which could be invoked out of an interrupt context and thus cannot acquire a mutex itself.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80548.json"
}