CVE-2026-80552

Source
https://cve.org/CVERecord?id=CVE-2026-80552
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80552.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80552
Downstream
Published
2026-08-26T14:37:21.178Z
Modified
2026-08-28T03:47:28.984949774Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
s390/vfio_ccw: Ensure index for read/write regions are within range
Details

In the Linux kernel, the following vulnerability has been resolved:

s390/vfio_ccw: Ensure index for read/write regions are within range

The introduction of the capability chain rightly clamped the region indexes to the range of the capabilities itself, but neglected to do so for the existing read/write regions which should also be enforced.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80552.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
db8e5d17ac03a65e2e0ee0ba50bf61a99741d871
Fixed
3acbedf5c0b8e0971f0de423c05cc02bbf6ddb99
Fixed
d3b1e38404b22df5a1f93019f2bb656feaad5ae3
Fixed
79ea5e0c4c8a9842ae85f45062d947b3297dfc07
Fixed
d597fa1273802941c7801202135976fecc29672b
Fixed
649badf3a2fd8929e40198603a2cb21b74c21700
Fixed
988d9b5be3c2c4baf9457ce8e11b477e13eb9fcf
Fixed
9f5f9a78fedc45bc29d6a0a64e3a3472361afae5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80552.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.2.0
Fixed
5.15.218
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.184
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.153
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.46
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80552.json"