HIGH 8.8 NVD
CVE-2026-80921
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 a
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: vsie: zero stale crypto bits
When shadowing crypto access bits from a format0 apcb (crycb 0 or 1),
the bits 64..255 are unchanged from whatever is in the vsie page in the
crycb and thus in the apcb. This gives a nested guest potential access
to a device no longer available. Zero out the remaining bits.
References
- https://git.kernel.org/stable/c/087c19cc60a8caa1a08e1e434c8be2caf6c27733
- https://git.kernel.org/stable/c/29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6
- https://git.kernel.org/stable/c/34d5b5b646c91cfb9338d7a12c955a70ffb8c66b
- https://git.kernel.org/stable/c/59d51550b5cb916bda037673a721a404b3b47a0d
- https://git.kernel.org/stable/c/7d23489f51109e3ebba5b5db8c5f0185af7b7fdf
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-09-09 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.