CVE-2026-89924

Source
https://cve.org/CVERecord?id=CVE-2026-89924
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89924.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89924
Downstream
Published
2026-09-16T10:32:17Z
Modified
2026-09-17T03:47:26Z
Summary
KVM: s390: Fix old_data leak in guest debug error path
Details

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Fix old_data leak in guest debug error path

__import_wp_info() allocates a per-watchpoint old_data buffer to back up the original guest memory contents. If a later watchpoint of the same KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data() jumps to the error label, which frees the wp_info array but not the old_data buffers of the entries that were imported successfully. Up to MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed request, and the request can be repeated.

Create error handling for cleaning up all created old_data memory areas.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89924.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
27291e2165b6de70c476b7b675308113edd69a60
Fixed
124c81ee610e1fbdd93d4399f88d9e28ba97a941
Fixed
e5ae7816e5ad145618f7fd568a0e8a94dd9f81f4
Fixed
c85d402553987777cc4742751437ea5dcbf98a7b
Fixed
5fbf319137735252eefa507193c9a619af5b7457
Fixed
4048d0a252163084794be3e37995b872c5178913
Fixed
f55e4d415d95342d5753e528e05a1e8623992c3f
Fixed
46cb8a273e2f853f89a78b59dbdff8787b6e1c86
Fixed
aa9c8e8baf1e765fa65b93212522c636f25d846f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89924.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.16.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89924.json"