CVE-2026-68454

HIGHCVSS 8.8/10EPSS 0.13%

Last modified

CVE-2026-68454 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest AISB location instead of virt_to_phys(page_address(NULL)).. EPSS estimates a 0.13% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest AISB location instead of virt_to_phys(page_address(NULL)).

Metrics

EPSS Probability
0.13%

3.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc, < f887df91826e72b570c5e9298e66dd929f09edde; >= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc, < 3ef3190e30601b2688bdc64169b938b8d7f42010; >= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc, < d48b9b096d11e31690c0a4988f65f21b64c01b2a; >= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc, < df72596278b0e22dac5ef2881e9221a3a2c4ed11; >= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc, < 124a3769c43713a11a93a821b313e61ad5110cb8; >= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc, < 3e3aa6da87d30a0064a17b836685cd43c90a3572
LinuxLinux6.0

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68454?
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest AISB location instead of virt_to_phys(page_address(NULL)).
How severe is CVE-2026-68454?
CVE-2026-68454 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.13% probability of exploitation in the next 30 days.
How do I fix CVE-2026-68454?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68454?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST