CVE-2026-80555

Source
https://cve.org/CVERecord?id=CVE-2026-80555
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80555.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80555
Downstream
Published
2026-08-26T14:37:22Z
Modified
2026-08-28T03:47:29Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H CVSS Calculator
Summary
s390/vfio_ccw: Free all memory if cp_init() fails
Details

In the Linux kernel, the following vulnerability has been resolved:

s390/vfio_ccw: Free all memory if cp_init() fails

The routine cp_free() is called to unpin/free any memory once an I/O is completed successfully, or if cp_prefetch() fails. But if cp_init() fails, and cp->initialized is not enabled, the same routine cannot be used to free all the memory.

An attempt to address this exists in ccwchain_handle_ccw(), where a single call to ccwchain_free() is made for the currently-processed CCW segment. But this will leak other segments (created as a result of a Transfer in Channel) that had been allocated as part of the same channel program.

Address this by performing the cleanup outside of the recursive ccwchain_handle_ccw()/ccwchain_loop_tic() logic.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80555.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8b515be512a2435bb8aedc6390cbe140167f9eb9
Fixed
276bd7ed34d56c48c65c43c0b08f2ee77029b2fa
Fixed
f9bcff265556796834122f95de16d52a8375206c
Fixed
17e01e342af74de12899c206dcc9ec90684703aa
Fixed
152fcb74a26804b70909381c6acc90595a0ae1c1
Fixed
6a917199aaf97904f5619afe3dfdacb155b03e8c
Fixed
32e3d364a7b8295120d37e6a6bd433d2de26f748
Fixed
4699b54fada156534cbb39834d47fc9374d7a1f5
Fixed
74186c2968f8f756ac3226b545b598457c910c75

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80555.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
5.10.267
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.218
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.185
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.154
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.46
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80555.json"