CVE-2026-80921

Source
https://cve.org/CVERecord?id=CVE-2026-80921
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80921.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80921
Downstream
Published
2026-09-09T16:19:42Z
Modified
2026-09-11T03:49:00Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
KVM: s390: vsie: zero stale crypto bits
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: vsie: zero stale crypto bits

When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80921.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6b79de4b056e5a2febc0c61233d8f0ad7868e49c
Fixed
d110b3297f11ef227098b8a82ade2d5f123b7d2f
Fixed
59d51550b5cb916bda037673a721a404b3b47a0d
Fixed
f6079dca67eccb5eabef9f72437948c66dc5131f
Fixed
087c19cc60a8caa1a08e1e434c8be2caf6c27733
Fixed
7d23489f51109e3ebba5b5db8c5f0185af7b7fdf
Fixed
935eeba276012916c76243e5cbb843efd8fdb75d
Fixed
d4bcd2df6d0d2af916b4fe1a533958778ea7c45b
Fixed
29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6
Fixed
34d5b5b646c91cfb9338d7a12c955a70ffb8c66b

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80921.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.10.269
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.220
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.187
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.156
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.108
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.49
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.13
Type
ECOSYSTEM
Events
Introduced
7.2.0
Fixed
7.2.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80921.json"