CVE-2026-80684

Source
https://cve.org/CVERecord?id=CVE-2026-80684
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80684.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80684
Downstream
Published
2026-08-28T06:52:50.703Z
Modified
2026-08-30T03:48:21.222298779Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: pci: Fix NULL dereference on AIBV allocation failure

The airqivcreate() can return NULL on failure, but the return value was never checked. If it fails, zdev->aibv will be NULL and fail when dereferenced in kvmzpciset_airq(). Add a NULL check and free the previously allocated AISB bit and zdev->aisb on failure.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80684.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc
Fixed
96099486b63985801c9c6ef22505e9aa635b2d20
Fixed
0a95abe964400771ad82b027d7b84a0d183cd0db
Fixed
df947d85e164a50a29d43a96e814f69ab1d0f7ed
Fixed
e137d082325bbcae780087b57501d38585e625d9
Fixed
d1a103dc9016c25e7423ce5841a5cc2df76d59f3
Fixed
8bf09b9b7d3232806df95f409581f8a9fd99a3fa

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80684.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80684.json"